Boardwise is a board portal for organizations that have to defend their governance record. The same standard applies to how we run the service: customer board data is hosted in Canada, encrypted at rest and in transit, protected by passkey authentication, and monitored continuously. This page describes our actual controls — and how to request the documentation behind them.
Last reviewed June 2026. For questions, contact [email protected].
Customer board data is hosted in Canada. Specifically, in Amazon Web Services' Canada Central region.
Compute (AWS EC2) and the managed PostgreSQL database (Crunchy Bridge) run in AWS Canada Central (ca-central-1), across Montreal-area availability zones. The database is reachable only over private VPC networking — it is not exposed to the public internet.
Uploaded board materials are stored in AWS S3 in ca-central-1, encrypted at rest (SSE-S3), with public access blocked and object versioning enabled. Your meeting packets and minutes stay in Canada.
Cloudflare provides DNS, CDN, WAF, and load balancing in front of the origin. TLS is terminated at the Cloudflare edge in full (strict) mode and re-encrypted to the origin.
A note on precision: your board data — the database and document storage — is hosted in Canada. A small number of supporting sub-processors (for example, transactional email and error monitoring) may process limited personal data such as names and email addresses elsewhere. The full list is below. Data residency reflects current production infrastructure and is described as fact, not offered as a contractual residency commitment.
We are specific about what is certified, and by whom.
Boardwise runs on AWS infrastructure that holds independent ISO/IEC 27001 and SOC 2 attestations covering the Canada Central region, among other programs. These certifications belong to AWS, the infrastructure provider — we inherit the controls of the platform we build on, and attribute them accordingly.
Boardwise's own security controls are designed to align with the SOC 2 Trust Services Criteria. We have not yet completed an independent SOC 2 examination. We would rather tell you exactly where we are than imply a report we do not hold. If a SOC 2 report is a procurement requirement for you, contact us — we are happy to discuss our roadmap.
AES-256 encryption at rest. EBS encryption-by-default is enabled region-wide for all production volumes; document storage uses S3 server-side encryption (SSE-S3).
TLS 1.2 or higher in transit. Traffic is served over HTTPS end to end, with TLS terminated at the Cloudflare edge and re-encrypted to the origin.
Boardwise ships passkey (WebAuthn) authentication on every account — biometrics or a hardware security key, with no password to phish or reuse. Role-based permissions govern what each director, administrator, or observer can see.
Administrative access to AWS is federated through AWS IAM Identity Center (SAML via Google Workspace), with MFA enforced across AWS, Google Workspace, GitHub, and our database and monitoring providers. Root usage is emergency-only with MFA. Access is revoked the same business day, and no later than 24 hours, after it is no longer needed.
An AWS CloudTrail organization trail (multi-region, with log-file validation) captures management events plus write and delete events on the customer storage bucket, delivered to a dedicated log bucket. In-app document access is tracked at the application layer. Logs are retained 90 days operational, one year for security and audit.
AWS GuardDuty, Security Hub, Amazon Inspector, AWS Config, and IAM Access Analyzer run across the environment for continuous threat and configuration monitoring.
BetterStack provides uptime monitoring and observability; AppSignal provides error tracking. Alerts fire on failed deploys, downtime, elevated error rates, and TLS expiry.
The database runs with high availability and automatic failover. Web instances are distributed across availability zones behind Cloudflare load balancing with health monitoring.
Point-in-time recovery plus a rolling backup schedule (20 daily, 8 weekly, 6 monthly). Restoration is tested quarterly via an automated restore task — backups you have not tested are not backups.
Hosts receive daily security updates via unattended-upgrades, with AWS Systems Manager Patch Manager managing staggered maintenance windows and compliance reporting.
Critical vulnerabilities are remediated within 7 days, high within 30 days, and medium and low in the next maintenance cycle.
We run regular automated application security scanning (Beagle Security) against the platform. Independent third-party penetration testing is on our security roadmap — our policy is to commission it at least annually and after significant architectural changes.
The third parties that help us run the service, and where customer board data lives.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Application hosting and document storage | Canada (ca-central-1) |
| Crunchy Data | Managed PostgreSQL database (Crunchy Bridge) | Canada (ca-central-1) |
| Cloudflare | DNS, CDN, WAF, load balancing | Global edge |
| Postmark | Transactional email | United States |
| Google Workspace | Email and identity provider for internal access | United States |
| AppSignal | Application error tracking | European Union |
| BetterStack | Uptime monitoring and observability | European Union |
| Stripe | Payment processing (billing only) | United States |
Customer board content — documents, minutes, and the database — is hosted with AWS and Crunchy Data in Canada. Other sub-processors handle operational metadata (such as delivery of a notification email or an error report containing a name and email address). Region reflects where each provider processes the relevant data to the best of our current knowledge; confirm specifics with us for a procurement review.
We monitor for security events continuously and maintain an incident-response process. In the event of a confirmed reportable breach, Boardwise notifies affected customers and regulators based on contractual, legal, and regulatory requirements, and targets notification without undue delay.
The questions security and procurement teams ask most.
All network traffic to and from the application is encrypted in transit using industry-standard TLS.
Inbound traffic is protected by Cloudflare, which provides TLS termination, DDoS protection, and web application firewall (WAF) capabilities at the network edge — mitigating common network-level and application-layer attacks before they reach the application.
Application services are hosted on Amazon Web Services in the Canada Central region, where network isolation, host-level security controls, and continuous monitoring are managed by the platform provider. Direct access to underlying infrastructure is restricted and controlled by the provider. Internal service-to-service communication is encrypted in transit, and administrative access to production is protected with strong authentication and access controls.
Administrative access requires multi-factor authentication across all critical systems, including hosting, source control, and corporate email.
Customers authenticate using passkeys or secure email login links. Password-based authentication is not supported. Single sign-on (SSO) options may be introduced in the future based on customer needs.
Security incidents are categorized by severity and potential impact to customer data, system integrity, and service availability, so they are prioritized and handled appropriately.
Low — no impact to customer data or system security (e.g. benign alerts, blocked attacks, false positives). Logged and reviewed; typically no customer notification.
Medium — may affect service availability or internal systems but no unauthorized access to customer data. Investigated promptly and remediated.
High — confirmed or suspected unauthorized access, disclosure, or alteration of customer data, or material impact to system security. Triggers immediate response, escalation to senior leadership, and customer notification when required.
All incidents are documented, investigated to determine root cause, and followed by corrective actions to reduce the likelihood of recurrence.
More detailed materials — security overview, penetration-test summary, sub-processor and data-processing details — are available to customers and prospects under confidentiality. Requests are logged, and we review each one individually before sharing the materials.
Request documentationSecurity questions, or to report a vulnerability: [email protected]. This page reflects current production infrastructure as last reviewed June 2026 and is updated as our infrastructure changes.