Make monday.com work with Microsoft 365 & SharePoint →
Client Portal Builder logo

Client Portal Builder

Gorilla Apps

658 installs, since August 18, 2024.   26 installs/month.   App updated July 15, 2026. Listing updated July 28, 2026.

Paid No touch

Create secure Client Portals directly on monday.com

Client Portal Builder lets you build, manage, and publish Client Portals directly on monday. Securely share board items, files, and more in password-protected Client Portals. Watch the ↗️ Getting Started video or visit ↗️ clientportalbuilder.com to learn more about the app.



DEMO PORTAL


↗️ clientportalbuilder.com/demo

Username 👉 perry@portal.com

Password 👉 #demoportal25



FEATURES


👨‍💼 Clients + Login

Manage clients in a single board, granting portal access via credentials or Google.


Board Access · ↗️ Watch Video

Define which boards, items, and columns each client can access.


📄 Pages + Content

Create portal pages and add content sections to your needs.


📋 Embed WorkForms

Embed your WorkForms and more into the portal.


🗄 Conditional Content · ↗️ Watch Video 

Show pages and sections to clients based on certain conditions.


🤖 Workflow Automations [NEW] · ↗️ Watch Video

Automate in between monday and your client portal.


✏️ Item Editing

Let clients update board columns on their own behalf.


💬 Item Comments · ↗️ Watch Video 

Collaborate and chat with clients on board items and exchange files.


Action Buttons · ↗️ Watch Video 

Add buttons to items so clients can trigger predefined automations.


🎨 Theme Settings

Make the client portal match your company branding.


🌐 Custom Domain · ↗️ Watch Video

Connect your client portal to your company's domain.


🔒 Security + Hosting · ↗️ Learn More

Your data stays securely hosted within your monday account and region.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

No
We do not currently commission formal recurring third-party penetration tests. We use code review, automated security scans performed as part of the monday app lifecycle, dependency and platform updates, and targeted security testing.

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
Security and privacy questions can be sent to hello@getgorilla.app.

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
Application redirects are limited to fixed application routes, monday authorization endpoints, and custom portal domains registered and verified for the relevant portal. User-provided external destinations are not accepted as arbitrary server-side redirect targets.

Does the app protect against mass parameter assignment attacks?

Yes
API request data is validated against Zod schemas and allowed fields are mapped explicitly. Request objects are not assigned directly to stored records.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
React escapes rendered values by default, Markdown is rendered without raw HTML support, and backend inputs are schema-validated. Customer-configured embedded content is isolated in an iframe.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Not answered

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Yes. Our incident-response process requires us to notify monday.com through its support or security escalation channel when an incident affects monday.com data, authorization tokens, or platform integrity.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Yes. We review dependency and platform updates, prioritize security fixes according to risk, test relevant changes before release, and monitor the security scans performed during monday app deployments.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

No
No. Gorilla Apps is not ISO/IEC 27001 certified.

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No
No. Client Portal Builder is not offered as a HIPAA-compliant service, and Gorilla Apps does not enter into Business Associate Agreements for the app.

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

No
No. Gorilla Apps does not currently hold a SOC 2 report or SOC 3 certification.

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
Yes. Gorilla Apps provides a GDPR-focused Privacy Policy and a Data Processing Addendum for Client Portal Builder, uses data-processing terms with its subprocessors, supports applicable data-subject and deletion obligations, and documents international-transfer safeguards. The DPA is available at https://getgorilla.app/dpa.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Yes
Yes. Portal configuration, client records, and board content are primarily stored in or retrieved from the customer's monday account. Limited data is processed outside monday.com to operate the service: Cloudflare provides routing, request processing, temporary storage, caching, analytics, and logging; Render stores encrypted app-lifecycle and subscription records; Hetzner stores encrypted backups; and Twilio SendGrid delivers transactional installation email. Optional Google sign-in processes identity data when enabled. Board data is retrieved through monday APIs as needed and is not retained as a separate portal database copy.

Where does the app store logs data?

other
Application logs are stored in monday.com's hosting environment and Cloudflare Workers Observability. Selected Cloudflare logs are also archived in a Cloudflare R2 bucket for up to 90 days. Workers Observability retains logs for up to 7 days.

Where does the app store the app data?

monday

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Not answered

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Yes. Customer content and client accounts are stored in the relevant customer's monday.com account. Operational records outside monday.com are logically separated using tenant, account, and portal identifiers, and access is subject to authorization checks.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Not answered

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Yes. Production and Customer Data access is limited to the two Gorilla Apps operators and only where needed to operate, secure, or support the service. Individual accounts are used, and access is removed when it is no longer required.

Reviews

June 24, 2026

DP: This is the best app we use on Monday.com. We can't live without it! We appreciate the attentiveness of the developer, Simon very much.

February 26, 2026

WW: Simon and the team have been amazing! This app intergrates so well with how we connect with our customers! Thank you!

August 29, 2025

WB: We tries several different portal solutions. This one was the only one that had the 1:1 client option. Great!

June 4, 2025

TK: The team is the best at support and helping get things solved. Highly recommend

Historical data

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

Total number of installs

Change in total number of installs in last 1 day(s)

Compares the number of installs on each date with 1 days previously:

Max
Min
Current

Change in total number of installs in last 7 day(s)

Compares the number of installs on each date with 7 days previously:

Max
Min
Current

Change in total number of installs in last 30 day(s)

Compares the number of installs on each date with 30 days previously:

Max
Min
Current

Change in total number of installs in last 90 day(s)

Compares the number of installs on each date with 90 days previously:

Max
Min
Current

Change in total number of installs in last 180 day(s)

Compares the number of installs on each date with 180 days previously:

Max
Min
Current

Ratings history

Categories history

Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.

In "Featured" category?

In "Editor's choice" category?

In "Trending this week" category?

App metadata

ID: 10000574App ID: 10162208Listing updated: July 28, 2026