Trust
Trust & Security at Boardenance
Boards entrust us with sensitive governance records. This page is maintained by the Boardenance team and describes the security and privacy practices we have in place today. It is editable content owned by Boardenance, not an independent certification or audit.
Authentication & access
Every account is protected by email-and-password or Google sign-in. Passwords are checked against the Have I Been Pwned breach database during signup and password changes to prevent reuse of compromised credentials.
Inside an organization, access is granted by role (org admin, billing owner, auditor, board admin, secretary, member, guest). Every record in our database is gated by row-level security policies tied to those roles — users only see boards, meetings, minutes, and submissions they have been explicitly added to.
Encryption
All traffic to Boardenance is served over HTTPS (TLS 1.2+). Data at rest in our managed Postgres database and object storage is encrypted by the platform provider.
Sensitive integration tokens (Zoom OAuth access and refresh tokens) and invitation tokens are restricted at the column level — only backend service code, not user sessions, can read them.
Where your data lives
Boardenance runs on Lovable Cloud, which provisions a managed Supabase Postgres database, file storage, and authentication for this application. Application code executes on Cloudflare's serverless edge runtime.
Files (agenda attachments, board packets, recordings, training certificates, handbooks, policies) are stored in private buckets that require a signed URL or an authenticated request to download. The only public bucket is org branding (logos) used on public board sites.
Public vs private content
Each organization controls what is published on its public page at boardenance.com/p/<org>. Only meetings, agendas, handbooks, and policies that an org admin has explicitly marked public appear there. Executive-session segments, drafts, and internal notes remain visible only to authorized members.
Zoom host start URLs and meeting passwords are never exposed to general organization members — only board members and invited meeting guests can retrieve them.
Subprocessors
We rely on a small set of vendors to operate the service:
- Lovable Cloud / Supabase — application database, authentication, and file storage.
- Cloudflare — application hosting, edge runtime, and DNS.
- Zoom — optional video meeting creation when an organization connects its Zoom account.
Each organization may connect additional integrations (e.g. Google sign-in) on an opt-in basis.
Cookies & analytics
Boardenance uses session cookies required for authentication and to remember your preferences. See our Cookie Notice for details.
Retention & deletion
Audit logs are retained for 90 days on the Free plan and one year on the Pro plan, then automatically deleted. Other org content is retained for the lifetime of the organization. Org admins can delete boards, meetings, policies, and member records directly from the app; contact us for full account deletion or data export requests.
Reporting a security issue
If you believe you have found a vulnerability, please email security@boardenance.com with reproduction steps. We acknowledge reports within two business days and ask that you give us a reasonable window to remediate before public disclosure.
Need a signed DPA, subprocessor list update, or details for a vendor security review? Email legal@boardenance.com.
This page is editable content maintained by Boardenance. It describes current product capabilities and is not a representation of independent certification or audit. Specific contractual commitments are governed by your Terms of Service and Privacy Policy.