Security

Security at I'mBoard

We protect board data with modern, practical controls: TLS encryption, encrypted storage, least-privilege access, signed file links, audit trails, and hardened app defaults.

At a glance

What we do today

Encryption

TLS for all connections in transit; encrypted storage for DB and files at rest.

Access control

Private by default, role-based permissions, least-privilege IAM for infrastructure.

Signed file links

Time-limited, signed S3 URLs for file access; no public links in production.

Auditability

Board-pack version history and key actions are logged for traceability.

App hardening

CSP with script hashes, Helmet security headers, input validation/sanitization.

Demo isolation

A separate, read-only seeded workspace—no customer data in the demo.

Data Protection

Encryption & data handling

Specific controls that protect board documents, metrics, and discussions

TLS in transit

All app, API, and DB connections use HTTPS/TLS. HSTS and modern ciphers are preferred.

Encrypted storage

Database encryption via managed provider; file storage on AWS S3 with KMS server-side encryption.

Keys & secrets

Secrets managed via cloud services; never stored in code or repos.

Signed access

Time-boxed, signed URLs for file delivery; access is revoked when links expire.

Data ownership

It’s your data—export on demand; deletion on request per retention policy.

No public links

Production forbids open/public sharing endpoints to reduce exposure.

Account security

Authentication, authorization, and session controls

Passwordless sign-in

Email verification codes or Google sign-in; both issue short-lived JWTs (single-factor today).

MFA & enterprise SSO (roadmap)

TOTP/WebAuthn MFA and enterprise SSO (Google Workspace/Microsoft Entra/OIDC) are on the roadmap.

Roles & permissions

Private by default. Directors, observers, counsel, and executives receive only necessary access.

Session management

Token refresh with inactivity timeouts; sessions invalidated on credential reset.

Application Security

Secure by default

Hardening in the app and development workflow

Hardened headers & CSP

Helmet security headers and Content Security Policy with script hashes to reduce XSS risk.

Validation & sanitization

Strong input validation (Zod) and sanitization throughout the app.

Abuse controls

Rate-limiting and sensible defaults to deter automated abuse.

Audit trails

Key actions and board-pack versions are recorded for review and compliance needs.

Testing

Jest unit tests and Playwright end-to-end tests on CI/CD.

Solo build, smaller surface

Engineered by a solo founder; no external contractors, minimizing access vectors.

Infrastructure

How the platform is built

Built on trusted platforms

Managed infrastructure reduces patch and ops risk while preserving speed. Logs are collected (Winston) and deployments run through CI/CD.

This describes how the platform is assembled — it is not the complete vendor list. See Subprocessors and Independent controllers below for every provider that receives data.

Managed hosting

The app runs on Fly.io managed infrastructure (US, iad) — no self-managed servers to patch.

Managed database

MongoDB Atlas (us-east-1) with encryption at rest and operational safeguards.

Encrypted file storage

Amazon S3 (us-east-1) with KMS server-side encryption and signed-URL delivery.

Ships through CI/CD

Automated checks run on every change; production is not edited by hand.

AI/ML Data Handling

Structured first; AI-ready by design

We keep AI usage scoped and transparent. Data sent to providers is minimized and tied to the features you opt into.

AI providers do not train on your data. Inputs to our LLM providers may be retained for up to 30 days for abuse monitoring, then deleted. Document OCR is processed by Amazon Bedrock in us-east-1 and is not retained.

How Document Search protects your data →

Structured reporting

Forms create clean JSON schemas. Dashboards render from structured data—not arbitrary PDFs.

LLMs for assistive tasks

OpenAI for classification/summarization and Anthropic for portfolio insights; prompts grounded in your structured data.

Search & OCR

Embeddings via OpenAI (text-embedding-3) and Atlas Vector Search; document OCR via Amazon Bedrock (us-east-1).

Isolation

Demo workspace is separate and seeded; no customer data is used for training.

Governance & roadmap

Clear responsibilities and what’s next

Our responsibilities

App & infrastructure security, encryption, access control, logging, and incident response.

Breach notification

We notify affected customers of confirmed data breaches within 72 hours of confirmation.

Customer responsibilities

Manage who you invite; follow strong identity practices; classify what you share.

Responsible disclosure

Report issues to security@imboard.ai. We acknowledge quickly and keep you informed.

What’s next

MFA (TOTP/WebAuthn), enterprise SSO (Google Workspace/Microsoft Entra/OIDC), and a formal SOC 2 program. Timeline will be published once dates are locked.

Where your data is processed

Your board documents, financial data, meeting records, and account information are stored and processed in United States regions. Our core infrastructure runs entirely in the US — application hosting (Fly.io, iad), database (MongoDB Atlas, us-east-1), document storage (Amazon S3, us-east-1), and AI document processing (Amazon Bedrock, us-east-1).

A limited set of supporting services process operational and security data — such as IP addresses for bot protection, phone numbers for verification, product analytics, and error diagnostics — and may process it outside the United States. These services never receive your board documents or financial data.

Subprocessors

Providers that process customer data on our instruction, under a data processing agreement.

Amazon Web Services

Document storage, AI document processing (Bedrock, us-east-1), threat detection

MongoDB Atlas

Managed database & vector search (us-east-1)

Fly.io

Application hosting (US, iad)

OpenAI

Document classification & summarization (US)

Anthropic

AI-generated portfolio insights (US)

SendGrid

Transactional email (US)

Kickbox

Email deliverability verification (US-default; EU/UK SCCs for cross-border)

Sentry

Server error reporting — stack traces & request metadata; never board documents

Independent controllers & onward disclosures

These providers determine their own purposes for the data they receive; they are not our subprocessors. Each receives only what its function requires — never board documents or financial data.

Google

Sign-in, optional Drive/Sheets, product analytics

Cloudflare Turnstile

Bot protection on public pages (IP + token)

Twilio

SMS phone verification (optional)

LemonSqueezy

Payments (Merchant of Record)

LogRocket

Product analytics & session replay — privacy-masked; board content redacted before capture

Microsoft Clarity

Session analytics on the marketing site

These providers may process data outside the United States and receive only operational data — never board documents or financial data. LogRocket session recordings are privacy-masked: document text, form inputs, and network payloads are redacted before capture.

Version 2.3 · Last updated: July 2026

Questions or questionnaires? security@imboard.ai · Privacy requests: privacy@imboard.ai

Ready to see it in action?

Explore the Live Demo (no signup) or start your 14-day free trial.