Australian hosting
All data is hosted on Microsoft Azure in Australia East (Sydney). Your board's data stays in Australia.
Encrypted end-to-end
TLS 1.2+ for everything in transit; stored data encrypted at rest at the Azure storage layer (AES-256).
Role-based access
Four roles plus per-item confidential restrictions, so people see only what they're authorised to.
Full audit trail
Logins, document access, and changes to governance records are logged and available to administrators.
Your data belongs to you
You own your data. Everything your organisation puts into BoardTable — meeting papers, minutes, registers, declarations and uploaded documents — remains your organisation's property at all times. BoardTable is the custodian, not the owner.
We will never sell your data, share it with third parties for marketing, or use it to train AI models. Your data is used only to provide the BoardTable service to you. You can export your data at any time in standard formats, and you may request complete deletion when you close your account — we remove it from active systems within 30 days, and from backups as backup cycles roll over thereafter.
Hosting & infrastructure In place
BoardTable is hosted exclusively on Microsoft Azure, Australia East (Sydney). We do not use offshore servers — your data resides in Australia and does not leave the country.
We build on Azure precisely because its underlying platform carries independent accreditations that no small vendor could achieve alone. Azure's infrastructure is certified against ISO/IEC 27001, 27017 and 27018, SOC 1, SOC 2 Type II and SOC 3 and PCI DSS, and is assessed under the Australian Government's IRAP framework. To be clear about what that means: these are Azure's certifications for the data-centre and cloud platform we run on — not BoardTable's own organisational certifications. BoardTable's own SOC 2 programme is on our roadmap (below).
Encryption In place
In transit
All connections use TLS 1.2 or higher. We enforce HTTPS across every endpoint and send HSTS headers to prevent protocol-downgrade attacks; older TLS versions and weak ciphers are disabled.
At rest
Your data — the database, uploaded documents and backups — is stored on Microsoft Azure storage, which encrypts data at rest with AES-256 at the storage layer, by default. This protects your data against physical access to the underlying disks. A further layer of application-managed encryption, where the database is protected with keys under our own control, is On our roadmap.
Passwords
Passwords are never stored in plaintext. We hash them with bcrypt (work factor 10), which makes brute-force attacks computationally infeasible.
Access controls In place
BoardTable uses a role-based access-control model with four roles, so people see only what their role allows:
- Administrators manage the organisation's account, users, meetings and all governance records.
- Staff (e.g. a company secretary or EA) can build meetings, agendas and packs, but don't have full account control.
- Chair has director access plus chair-specific abilities such as finalising minutes.
- Directors access meeting materials, submit conflict-of-interest declarations, and view the documents they've been given permission to see.
A member's effective permissions come from their role in your organisation, and individual agenda items or documents can be marked confidential and restricted to named people. Each request is authenticated with a signed JWT bearer token that expires and requires re-authentication, and every request re-checks the member's current role against the database — so a role change or removal takes effect immediately.
Two-factor authentication In place
BoardTable supports time-based one-time-password (TOTP) two-factor authentication for every account, compatible with apps such as Google Authenticator and Authy. Administrators can require 2FA across their whole organisation, and we strongly recommend it for all board members.
Audit logging In place
BoardTable records significant events — user logins and failed login attempts, document access and downloads, changes to meeting and governance records, and user/role changes and administrative actions. These logs are retained and made available to your administrators on request, giving your board a clear record of who did what, and when.
Backups In place
BoardTable takes regular automated backups of your data, held securely within our Australian Azure environment, so your board's records can be restored in the event of a problem. Administrators can also export a full copy of your organisation's data at any time from the Backup & Export tools in the app.
Handling a security incident In place
If a data breach affecting personal information ever occurred, we would act to contain it promptly, assess whether it is likely to result in serious harm, and notify affected organisations without undue delay. We will comply with our obligations under the Notifiable Data Breaches (NDB) scheme administered by the Office of the Australian Information Commissioner (OAIC), including notifying the OAIC and affected individuals where the scheme requires it, and we'll give affected organisations a written summary of what happened and what we did about it.
Superadmin & staff access In place
BoardTable is operated by a very small team, and staff access to your data is limited to what's needed to run and support the service, under a principle of least privilege. The platform has a single superadmin role, held only by BoardTable's operators, which exists to provision new organisations and provide technical support. Superadmins are bound by confidentiality and will never read, disclose or act on the contents of your board's papers, minutes or registers except where strictly necessary to resolve a support request you've raised, or where required by law.
Reporting a security or privacy concern
If you believe you've found a security vulnerability, or you're concerned data may have been exposed or accessed improperly, email hello@boardtable.com.au with as much detail as you can safely share. We operate a responsible-disclosure approach, will acknowledge your report within 2 business days, and will keep you informed as we investigate. Please give us a reasonable opportunity to address an issue before disclosing it publicly.
Our security roadmap
We'd rather be honest about where we're headed than imply we're further along than we are. These are the security investments we're working towards — they are not in place yet:
What's coming
- Application-managed encryption — a further layer of encryption on top of Azure's, with keys under our own control.
- Independent penetration testing — engaging an external security firm to test the platform on a regular cycle.
- SOC 2 Type II — establishing BoardTable's own controls programme and pursuing independent attestation across Security, Availability and Confidentiality.
- A formal, documented incident-response plan — building on the obligations and practices described above.