Security Protocol
Last updated: July 8, 2026
Overview
BoardRecord is built to hold institutional records for condo and co-op boards — bid packages, vendor correspondence, board decisions, and financial approvals. We treat every piece of data as if it could be subpoenaed, because it can. This page describes the security infrastructure that protects your building's project record.
Questions about our security practices? Contact security@boardrecord.com.
Encryption
- All data encrypted at rest using AES-256 with keys managed through hardware security modules (HSMs).
- All data encrypted in transit using TLS 1.3 for every connection between your browser and our servers.
- Database field-level encryption for sensitive fields including email content and document attachments.
- Encryption keys are rotated on a regular schedule and are never stored alongside encrypted data.
Access Controls & Authentication
- Role-based access control (RBAC) scoped to each building workspace — board members, managers, and administrators each see only what they should.
- Multi-factor authentication (MFA) available for all accounts.
- Every access event — logins, document views, exports, and permission changes — is logged and auditable.
- Session management with automatic timeout and device-level revocation.
Data Ownership & Residency
- Your organization retains full ownership of all data uploaded to or generated within BoardRecord.
- Configure data residency, retention, and export policies to meet local regulatory requirements.
- Full data export available at any time in standard formats (JSON, CSV, PDF).
- Upon account deletion, all data is permanently removed within 30 days.
Infrastructure
- Hosted on AWS with infrastructure isolated per tenant at the network level.
- Automated backups with point-in-time recovery and geographic redundancy.
- DDoS protection and web application firewall (WAF) for all public endpoints.
- Regular penetration testing and vulnerability scanning by independent third parties.
Vendor & Email Security
- Whitelisted sender verification for inbound email ingestion — only recognized addresses are processed.
- Attachment scanning and malware detection before documents enter the project record.
- Vendors interact exclusively via email and never have direct platform access.
- SPF, DKIM, and DMARC validation on all inbound and outbound email.
Audit & Compliance
- Immutable audit trail records every action taken on project records, documents, and communications.
- Audit logs cannot be modified or deleted by any user, including administrators.
- Export-ready audit reports for board meetings, legal proceedings, and compliance reviews.
- Data processing practices aligned with CCPA/CPRA, GDPR, and PIPEDA requirements.
Responsible Disclosure
If you discover a security vulnerability in BoardRecord, please report it responsibly. Contact security@boardrecord.com with details of the issue. We will acknowledge receipt within 48 hours and work with you to understand and resolve the issue before any public disclosure.
Related Policies
For information about how we collect and use your data, see our Privacy Policy. For the terms governing your use of the Service, see our Terms of Service.