Security
Security at I'mBoard
We protect board data with modern, practical controls: TLS encryption, encrypted storage, least-privilege access, signed file links, audit trails, and hardened app defaults.
At a glance
What we do today
TLS for all connections in transit; encrypted storage for DB and files at rest.
Private by default, role-based permissions, least-privilege IAM for infrastructure.
Time-limited, signed S3 URLs for file access; no public links in production.
Board-pack version history and key actions are logged for traceability.
CSP with script hashes, Helmet security headers, input validation/sanitization.
A separate, read-only seeded workspace—no customer data in the demo.
Data Protection
Encryption & data handling
Specific controls that protect board documents, metrics, and discussions
TLS in transit
All app, API, and DB connections use HTTPS/TLS. HSTS and modern ciphers are preferred.
Encrypted storage
Database encryption via managed provider; file storage on AWS S3 with KMS server-side encryption.
Keys & secrets
Secrets managed via cloud services; never stored in code or repos.
Signed access
Time-boxed, signed URLs for file delivery; access is revoked when links expire.
Data ownership
It’s your data—export on demand; deletion on request per retention policy.
No public links
Production forbids open/public sharing endpoints to reduce exposure.
Account security
Authentication, authorization, and session controls
Passwordless sign-in
Email verification codes or Google sign-in; both issue short-lived JWTs (single-factor today).
MFA & enterprise SSO (roadmap)
TOTP/WebAuthn MFA and enterprise SSO (Google Workspace/Microsoft Entra/OIDC) are on the roadmap.
Roles & permissions
Private by default. Directors, observers, counsel, and executives receive only necessary access.
Session management
Token refresh with inactivity timeouts; sessions invalidated on credential reset.
Application Security
Secure by default
Hardening in the app and development workflow
Hardened headers & CSP
Helmet security headers and Content Security Policy with script hashes to reduce XSS risk.
Validation & sanitization
Strong input validation (Zod) and sanitization throughout the app.
Abuse controls
Rate-limiting and sensible defaults to deter automated abuse.
Audit trails
Key actions and board-pack versions are recorded for review and compliance needs.
Testing
Jest unit tests and Playwright end-to-end tests on CI/CD.
Solo build, smaller surface
Engineered by a solo founder; no external contractors, minimizing access vectors.
Infrastructure
How the platform is built
Built on trusted platforms
Managed infrastructure reduces patch and ops risk while preserving speed. Logs are collected (Winston) and deployments run through CI/CD.This describes how the platform is assembled — it is not the complete vendor list. See Subprocessors and Independent controllers below for every provider that receives data.
Managed hosting
The app runs on Fly.io managed infrastructure (US, iad) — no self-managed servers to patch.
Managed database
MongoDB Atlas (us-east-1) with encryption at rest and operational safeguards.
Encrypted file storage
Amazon S3 (us-east-1) with KMS server-side encryption and signed-URL delivery.
Ships through CI/CD
Automated checks run on every change; production is not edited by hand.
AI/ML Data Handling
Structured first; AI-ready by design
AI providers do not train on your data. Inputs to our LLM providers may be retained for up to 30 days for abuse
monitoring, then deleted. Document OCR is processed by Amazon Bedrock in us-east-1 and is not retained.
Structured reporting
Forms create clean JSON schemas. Dashboards render from structured data—not arbitrary PDFs.
LLMs for assistive tasks
OpenAI for classification/summarization and Anthropic for portfolio insights; prompts grounded in your structured data.
Search & OCR
Embeddings via OpenAI (text-embedding-3) and Atlas Vector Search; document OCR via Amazon Bedrock (us-east-1).
Isolation
Demo workspace is separate and seeded; no customer data is used for training.
Governance & roadmap
Clear responsibilities and what’s next
App & infrastructure security, encryption, access control, logging, and incident response.
We notify affected customers of confirmed data breaches within 72 hours of confirmation.
Manage who you invite; follow strong identity practices; classify what you share.
Report issues to security@imboard.ai. We acknowledge quickly and keep you informed.
MFA (TOTP/WebAuthn), enterprise SSO (Google Workspace/Microsoft Entra/OIDC), and a formal SOC 2 program. Timeline will be published once dates are locked.
Where your data is processed
Your board documents, financial data, meeting records, and account information are stored and processed in United States regions. Our core infrastructure runs entirely in the US — application hosting (Fly.io, iad), database
(MongoDB Atlas, us-east-1), document storage (Amazon S3, us-east-1), and AI document
processing (Amazon Bedrock, us-east-1).
A limited set of supporting services process operational and security data — such as IP addresses for bot protection, phone numbers for verification, product analytics, and error diagnostics — and may process it outside the United States. These services never receive your board documents or financial data.
Subprocessors
Providers that process customer data on our instruction, under a data processing agreement.
Amazon Web Services
Document storage, AI document processing (Bedrock, us-east-1), threat detection
MongoDB Atlas
Managed database & vector search (us-east-1)
Fly.io
Application hosting (US, iad)
OpenAI
Document classification & summarization (US)
Anthropic
AI-generated portfolio insights (US)
SendGrid
Transactional email (US)
Kickbox
Email deliverability verification (US-default; EU/UK SCCs for cross-border)
Sentry
Server error reporting — stack traces & request metadata; never board documents
Independent controllers & onward disclosures
These providers determine their own purposes for the data they receive; they are not our subprocessors. Each receives only what its function requires — never board documents or financial data.
Sign-in, optional Drive/Sheets, product analytics
Cloudflare Turnstile
Bot protection on public pages (IP + token)
Twilio
SMS phone verification (optional)
LemonSqueezy
Payments (Merchant of Record)
LogRocket
Product analytics & session replay — privacy-masked; board content redacted before capture
Microsoft Clarity
Session analytics on the marketing site
These providers may process data outside the United States and receive only operational data — never board documents or financial data. LogRocket session recordings are privacy-masked: document text, form inputs, and network payloads are redacted before capture.
Version 2.3 · Last updated: July 2026
Questions or questionnaires? security@imboard.ai · Privacy requests: privacy@imboard.ai
Ready to see it in action?
Explore the Live Demo (no signup) or start your 14-day free trial.