Portal Hound

Portal Hound for SaaS companies

Internal admin tools for your offshore team, from one address your security team can allowlist.

Your internal admin, billing and support tooling is the most sensitive surface you have. Portal Hound gives offshore teams named access to the tools you approve, from one company-owned U.S. address that your security stack can allowlist, with a log of every session.

The problem

Internal tools reached from home connections worldwide look like an attack.

Security teams want internal admin tools restricted to known addresses. Offshore staff on home ISPs make that impossible, so the restriction gets dropped, and now the tool that can read any customer's data is open to the whole internet, protected by passwords alone.

You can't allowlist a hundred home ISPs

So the internal tool ends up reachable from anywhere, which is the thing the security policy said not to do.

Vendor consoles and cloud dashboards

Stripe, AWS, Datadog and the rest each react to logins from many countries, and each is a breach waiting to happen under a shared login.

SOC 2 asks who had access

Auditors want to see named users, controlled access paths and logs. Home connections and shared logins give them none of that.

How it works

One button for workers. Full control for you.

You approve the portals

Add each platform your team works in. Portal Hound suggests the domains it needs, and nothing is reachable until you approve it.

Workers press Connect

They install a small app for Windows or Mac, sign in with their work email, and connect. There's nothing to configure.

Only approved portals go through

Those platforms are reached through your company's U.S. gateway, tied to that person and logged. Email, banking and everything else use the worker's own connection.

Platforms

The portals these teams approve first.

Any web platform can be approved. These are typical for saas and software companies.

Your internal admin toolsStripe, Chargebee and billing dashboardsAWS, GCP and Azure consolesDatadog, Sentry and observabilityZendesk, Intercom and support toolsSalesforce and HubSpotOkta and Google Workspace adminVendor and partner portals

What you get

Allowlist one address, keep named SSO users, get a log for the auditor.

  • Restrict internal tools to your Portal Hound address; offshore staff reach them through it under their own SSO users.
  • Every session is tied to a person and logged, with no page contents recorded.
  • The gateway never decrypts traffic, so your existing TLS, SSO and MFA are untouched.
  • Revoke one person in one click; your security team sees a single address, not a hundred.
Portal Hound admin console

Requirements

Portal Hound is for teams already allowed to work offshore.

It controls and records how your team reaches portals. It doesn't change who is allowed to use them, or where from.

Your agreements must permit offshore access

Check your customer and vendor contracts and each portal's terms of use. Some restrict access from outside the country, or require it to be disclosed and approved first. Portal Hound is not a way around a portal's location rules.

Every person uses their own login

Your team members sign in to each platform with accounts issued to them, in the role they need. Portal Hound never shares, stores or fills in a login, and it isn't for working as somebody else.

Regulated data stays your responsibility

Customer data in your systems is governed by your privacy policy, your DPA commitments and frameworks like SOC 2. Portal Hound contributes access control and an access log; the rest of your program still applies.

Tell your team access is logged

The access log records which person reached which platform and when. Tell them, and follow the privacy and employment rules where they work.

Portal Hound doesn't guarantee access to any portal. The companies that run them decide who may use their systems. Full requirements.

Questions from saas and software companies

How does this interact with our SSO and MFA?

It doesn't. Portal Hound decides which sites go through the gateway and records who reached them. Sign-in, SSO and MFA happen exactly as before, end to end encrypted.

Can we put the Portal Hound address in our WAF or VPC allowlist?

Yes. Each customer's gateway has one fixed U.S. address, which is the point: it's a single address to allowlist for every offshore staff member.

Is this a replacement for a zero-trust product?

It's narrower. Portal Hound is for web portals only, with an allowlist, named identities and a log. If you already run a zero-trust platform for all traffic, you may not need it; many teams use it for the offshore group that platform doesn't cover well.

See Portal Hound with your own portals.

We'll show you the worker app and admin console, and talk through setting up a gateway for your team.