Trust
How we protect your governance data.
Boardroom is the boardroom-portal that publishes its safeguards instead of asking you to trust us. Every claim on this page is enforced in code we can show you.
Boardroom Lockbox — tamper-evident platform-admin log
Every time a Boardroom platform administrator touches your tenant's data, a row lands in your customer-visible activity log with a mandatory reason and a cryptographic chain seal. Inspired by Microsoft's Customer Lockbox, adapted for the boardroom domain, where board records are corporate records.
Mandatory rationale
Append-only chain
row_hash = HMAC-SHA256(secret, payload || prev_hash)Tampering breaks the chain immediately and our verification cron pages on the first mismatch.
Customer-visible
/org/<tenant>/admin-activity with action name, reason, and ticket reference. The platform admin's identity is masked.Retention: 7 years (board records are corporate records, longer than the SOC 2 12-month minimum).
Published permission matrix
Below is the default access matrix enforced by can(actor, action, resource, state) on every server action. C entries are configurable per organisation, but the defaults shipped never give an admin sight of whistleblower disclosures or executive-session minutes.
| Capability | Admin | Director | Chair | Comm Chair | Comm Member | Corp Sec | Officer | Observer | Auditor | Counsel | Guest |
|---|---|---|---|---|---|---|---|---|---|---|---|
Pack, distributed | ✓ | R | R | R | R | ✓ | R | R | C | C | — |
Pack, draft (pre-distribution) | ✓ | — | C | C | — | ✓ | — | — | — | C | — |
Voting Committee members vote only on resolutions of their own committee | — | ✓ | ✓ | ✓ | ∗ | — | — | — | — | — | — |
Resolution sign | — | ✓ | ✓ | ✓ | ∗ | C | — | — | — | — | — |
Minutes, post-adoption edit Both signatures land in the admin audit chain | 2P | — | 2P | — | — | 2P | — | — | — | — | — |
Quorum override | 2P | — | 2P | — | — | 2P | — | — | — | — | — |
Whistleblower disclosures Visible only to the Audit Committee Chair. Even platform administrators are denied. | — | — | — | ✓ | — | C | — | — | — | C | — |
Director compensation table Full table visible only to the Remuneration Committee Chair | ✓ | C | ✓ | C | — | ✓ | — | — | — | R | — |
Executive session minutes True in-camera: no admin / Corporate Secretary access without an explicit invite | — | ✓ | ✓ | ✓ | ✓ | — | — | — | — | — | — |
Litigation matters General Counsel role (officer_kind='GC') also allowed | — | — | ✓ | — | — | ✓ | — | — | — | ✓ | — |
Conflict register, all rows Own COI row is always visible to its owner | ✓ | C | ✓ | C | — | ✓ | — | — | — | R | — |
- ✓Full access
- RRead-only
- —Denied
- 2PTwo-person rule
- CConfigurable per organisation
- ∗Scoped to own committee
Published rate limits
Most board-portal vendors hide these numbers. We publish them so your developers can plan integrations and your procurement team can scope load. Enforced at the edge (Cloudflare), middleware (per-tenant + per-user + per-IP), and route layer (concurrency limit on PDF render / AI / WhatsApp blast).
| Plan | Requests / second | AI calls / month | WhatsApp / day |
|---|---|---|---|
| Free | 20 | — | — |
| Starter | 100 | 50 | 25 |
| Board | 200 | Unlimited | 200 |
| Enterprise | 500 | Unlimited | Unlimited |
429 responses carry Retry-After, X-RateLimit-Remaining, and X-RateLimit-Scope: tenant | user | ip so your developers can route around the right bucket.
Where your data lives
Boardroom runs on a single-region stack today. We say exactly where, rather than leaving it to a sales call.
Hosting & backups
Recovery targets (RTO / RPO)
Residency options
Subprocessor changes
Subprocessors
| Name | Purpose | Data shared | Optionality |
|---|---|---|---|
| Cloudflare | Ingress tunnel, edge TLS, DNS | Traffic in transit (TLS) | Core |
| Backblaze B2 | Encrypted off-site backups | AES-256 blobs (unreadable to B2) | Core |
| Stripe | Billing, card processing | Billing contact, subscription | Core (paid plans) |
| Resend | Transactional email | Recipient email, notification content | Core |
| OAuth sign-in; optional Calendar sync | OAuth identity claims | Core sign-in path | |
| Anthropic | AI summaries / ask-the-boardroom | The specific record's text, only on explicit click | Optional (BYOK supported) |
| Meta (WhatsApp Cloud API) | Notifications, per-tenant credentials | Recipient phone, message | Optional, off by default |
| Microsoft | Optional OAuth/SSO + calendar | OAuth identity claims | Optional |
| Sentry | Error monitoring | Stack traces (PII scrubbing on) | Optional, inert without a DSN |
| GitHub (ghcr.io) | CI-built container images | No customer data | Build/deploy chain only |
Encryption, retention, and your data
At rest
In transit
Retention
Exit
Sessions & devices
There is no password to phish, reuse, or leak — every sign-in is Google OAuth or your organisation's SAML identity provider.
Session lifetime
Per-device control
Remote-wipe, honestly scoped
Two-factor & recovery
Offline access & document protection
Offline reading
Per-document controls
Watermarking, honestly scoped
Redaction
AI and your data
Boardroom sells AI capacity, so here is exactly what that means for your data.
Explicit action only
Provider & training
Where the output lives
Tenant isolation, and redaction's real scope
Why we don't claim “zero-knowledge”
Some vendors claim it; we won't, because most of what makes Boardroom useful — search, AI summaries, formatted PDFs, notifications — requires the server to read your content. A product that truly never sees your data can't offer those features. What we do instead: every time a Boardroom administrator needs to touch your tenant's data, it requires a reason, lands in a log you can read, and is sealed so tampering with that log is detectable — see Boardroom Lockbox, above. We think a provable, verifiable trail is a more honest promise than a claim we can't back up in code.
Certifications & frameworks
Boardroom is architected against the controls in:
SOC 2 Type II
CC6.1 (logical & physical access), CC7.2 (system monitoring). Planned — audit scheduled after our first enterprise cohort. In the meantime, this page and our internal adversarial audit results are available for buyer risk review on request.
ISO 27001
Architected against Annex A controls. Certification planned to follow SOC 2, on the same evidence base.
GDPR
DPA available. Subject access requests honoured within 30 days via the tenant-export flow.
SOX §302 / §404
Two-person rule on minute amendments, hash-chained audit log of board resolutions and minute adoptions.
UK Corporate Governance Code (2024)
Whistleblower channel scoped to Audit Committee Chair only. Independent-director attribution drives recusal logic.
King IV (Principle 12)
Governance of technology: published security architecture, customer-visible platform-admin activity log.
Documents
Three tiers, honestly labelled — we don't put a “Download” button on anything that doesn't exist yet.
Public, no request needed
Available on request
Under NDA, once they exist
Request any of the above at balayogesh@gmail.com.
Security contact
Report a vulnerability or ask a procurement question to balayogesh@gmail.com. Acknowledgement within one business day; advisory triage within five.
We do not run a bug bounty. We do not pursue legal action against good-faith researchers acting under coordinated disclosure.