By default, anyone with a portal link can view the invoice, quote or customer portal it points to. If you'd like an extra layer of protection, Secure Portal Mode requires customers to verify their email address before they can see anything.
Turning it on
Go to Settings > Portal and enable the Secure Portal Mode toggle under Portal Permissions, then save. It applies to all your portals — invoices, quotes and customer statements.
What your customers see
When a customer opens a portal link, they're asked to confirm who they are:
1. They choose their email address from a partially hidden list of the contact people on their account (e.g. j***[email protected]).
2. Paidnice sends a secure verification link to that address.
3. Clicking the link opens the portal, and their browser stays verified — they won't be asked again on that device for the life of the link (30 days).
Only email addresses belonging to the customer's contact people can be verified, so someone who gets hold of a forwarded link can't view the portal without access to one of those inboxes.
Note: Paidnice users in your organisation can always open your portals while logged in, without going through verification. Make sure your customers' contact people have up-to-date email addresses before enabling this — a customer whose email isn't on file won't be able to verify.
