PortaBilling/PortaSwitch includes multiple layers of security controls for server access, user authentication, password management, and network-level protection.
All third-party open-source and commercial components included in the PortaBilling/PortaSwitch product are maintained and updated by PortaOne.
When PortaOne Support needs to access a service provider’s installation for monitoring or troubleshooting, they connect via secured internal access servers using multi-factor authentication. All actions are logged, allowing service providers to review what was done and when.
At the network level, PortaSwitch servers can be placed behind a firewall that permits connections only on required ports and from authorized IP addresses. You can block untrusted IP addresses and allow trusted ones with a single set of rules using the protected list on the servers. SSH access is additionally protected against brute-force attacks.
For web access, PortaBilling supports two-factor authentication (2FA), which requires a time-limited one-time password in addition to login credentials. Password storage, complexity requirements, and expiration policies are covered in the Password protection chapter.