1. Introduction
At BoardBreeze, we take the security of our users' data and our platform very seriously. This security policy outlines our commitment to protecting your information and the measures we take to ensure a secure environment.
2. Reporting Security Vulnerabilities
We appreciate the efforts of security researchers and users in reporting security vulnerabilities to us. If you believe you've found a security vulnerability in our services, we encourage you to report it to us as soon as possible.
To report a security vulnerability, please email help@appboardbreeze.com with the following information:
- A detailed description of the vulnerability
- Steps to reproduce the issue
- Any potential impact of the vulnerability
- Any suggestions for mitigating the vulnerability
We commit to:
- Acknowledging receipt of your vulnerability report within 48 hours
- Providing an initial assessment of the report within 5 business days
- Keeping you informed about our progress in addressing the vulnerability
- Notifying you when the vulnerability has been fixed
3. Security Measures
BoardBreeze implements the following security measures to protect your data:
- Data Encryption: All data in transit is encrypted using TLS/SSL. Sensitive data at rest is encrypted using industry-standard encryption methods.
- Authentication: BoardBreeze has no passwords. You sign in with a one-time 6-digit email code or with Google or Microsoft. Multi-factor authentication is required on every administrative account.
- Access Controls: We implement strict access controls to ensure that only authorized personnel can access sensitive data.
- Regular Security Audits: We conduct regular security audits and vulnerability assessments to identify and address potential security issues.
- Security Headers: We implement security headers to protect against common web vulnerabilities such as XSS, clickjacking, and MIME type sniffing.
- Secure Development Practices: We follow secure coding practices and conduct code reviews to identify and fix security issues early in the development process.
4. Sub-Processors and Third-Party Services
BoardBreeze uses the following third-party services to operate the platform. Each sub-processor is subject to appropriate data processing agreements and security standards.
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Audio storage (S3), speech-to-text transcription (Transcribe), email delivery (SES), serverless compute (Lambda), container hosting (ECS) | Audio recordings, transcription text | United States |
| Anthropic | AI-generated meeting minutes and Minutes Assistant chatbot (Claude API) | Meeting transcription text | United States |
| Supabase | Database, authentication, and row-level security | User account data, subscription status | United States |
| Stripe | Payment processing and subscription management | Payment card data (PCI-DSS compliant — BoardBreeze never stores card numbers) | United States |
| Vercel | Frontend hosting and serverless API functions | Web traffic, API requests | United States / Global CDN |
| Redis Cloud (Redis Ltd.) | Rate limiting and short-lived transcription job state | IP addresses, rate limit counters, job progress and transcript segments for up to 2 hours while a meeting is processed | United States |
| Sign in with Google; Google Drive export at the user's request (drive.file scope only); website analytics | Name and email at sign-in; minutes the user chooses to save to Drive; aggregate site usage | United States | |
| Microsoft | Sign in with Microsoft | Name and email at sign-in | United States |
| Cloudflare | Bot protection on sign-up (Turnstile) | Browser signals, IP address (no account data) | United States / Global |
| Twilio | Toll-free phone line for the AI concierge (1-844-786-2076) | Caller phone number, call audio | United States |
Audio recordings submitted for transcription are processed by AWS Transcribe and the resulting transcript is sent to Anthropic's Claude API solely for the purpose of generating meeting minutes and answering Minutes Assistant questions. Recordings and transcripts are deleted 4 days after upload. BoardBreeze does not use your meeting content to train AI models and does not sell or share it with any other third party. See our Privacy Policy for retention periods and your rights.
5. Data Breach Response
In the event of a data breach, we will:
- Promptly investigate the breach and take steps to contain and mitigate the impact
- Notify affected users as required by applicable laws and regulations
- Work with law enforcement and security experts as necessary
- Take steps to prevent similar breaches in the future
6. User Responsibilities
While we take extensive measures to protect your data, security is a shared responsibility. We encourage users to:
- Protect the email account and the Google or Microsoft account you use to sign in to BoardBreeze
- Keep your login credentials confidential
- Be vigilant about phishing attempts and suspicious communications
- Keep your devices and software up to date with the latest security patches
- Log out of your account when using shared or public computers
- Report any suspicious activities or potential security issues to us immediately
7. Changes to This Policy
We may update this security policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify users of any material changes to this policy.
8. Contact Us
To report a security vulnerability, email help@appboardbreeze.com. For general questions about our security practices or this policy, email help@appboardbreeze.com.