Trust Centre

Your board's most sensitive information, protected — and explained plainly

Board governance involves the most confidential data your organisation holds: financials, conflict-of-interest declarations, strategy, and in-camera minutes. Here is exactly how BoardTable protects it — with what's in place today kept separate from what's on our roadmap.

Last updated: 28 July 2026  ·  Security or privacy questions? hello@boardtable.com.au

We only claim what's real. Everything below marked In place is live today. Anything still being built is marked On our roadmap — we'd rather tell you plainly than dress up our maturity. If a claim here ever seems to fall short, email us and we'll fix the page or the product.

Australian hosting

All data is hosted on Microsoft Azure in Australia East (Sydney). Your board's data stays in Australia.

Encrypted end-to-end

TLS 1.2+ for everything in transit; stored data encrypted at rest at the Azure storage layer (AES-256).

Role-based access

Four roles plus per-item confidential restrictions, so people see only what they're authorised to.

Full audit trail

Logins, document access, and changes to governance records are logged and available to administrators.

Your data belongs to you

You own your data. Everything your organisation puts into BoardTable — meeting papers, minutes, registers, declarations and uploaded documents — remains your organisation's property at all times. BoardTable is the custodian, not the owner.

We will never sell your data, share it with third parties for marketing, or use it to train AI models. Your data is used only to provide the BoardTable service to you. You can export your data at any time in standard formats, and you may request complete deletion when you close your account — we remove it from active systems within 30 days, and from backups as backup cycles roll over thereafter.

Hosting & infrastructure In place

BoardTable is hosted exclusively on Microsoft Azure, Australia East (Sydney). We do not use offshore servers — your data resides in Australia and does not leave the country.

We build on Azure precisely because its underlying platform carries independent accreditations that no small vendor could achieve alone. Azure's infrastructure is certified against ISO/IEC 27001, 27017 and 27018, SOC 1, SOC 2 Type II and SOC 3 and PCI DSS, and is assessed under the Australian Government's IRAP framework. To be clear about what that means: these are Azure's certifications for the data-centre and cloud platform we run on — not BoardTable's own organisational certifications. BoardTable's own SOC 2 programme is on our roadmap (below).

Encryption In place

In transit

All connections use TLS 1.2 or higher. We enforce HTTPS across every endpoint and send HSTS headers to prevent protocol-downgrade attacks; older TLS versions and weak ciphers are disabled.

At rest

Your data — the database, uploaded documents and backups — is stored on Microsoft Azure storage, which encrypts data at rest with AES-256 at the storage layer, by default. This protects your data against physical access to the underlying disks. A further layer of application-managed encryption, where the database is protected with keys under our own control, is On our roadmap.

Passwords

Passwords are never stored in plaintext. We hash them with bcrypt (work factor 10), which makes brute-force attacks computationally infeasible.

Access controls In place

BoardTable uses a role-based access-control model with four roles, so people see only what their role allows:

A member's effective permissions come from their role in your organisation, and individual agenda items or documents can be marked confidential and restricted to named people. Each request is authenticated with a signed JWT bearer token that expires and requires re-authentication, and every request re-checks the member's current role against the database — so a role change or removal takes effect immediately.

Two-factor authentication In place

BoardTable supports time-based one-time-password (TOTP) two-factor authentication for every account, compatible with apps such as Google Authenticator and Authy. Administrators can require 2FA across their whole organisation, and we strongly recommend it for all board members.

Audit logging In place

BoardTable records significant events — user logins and failed login attempts, document access and downloads, changes to meeting and governance records, and user/role changes and administrative actions. These logs are retained and made available to your administrators on request, giving your board a clear record of who did what, and when.

Backups In place

BoardTable takes regular automated backups of your data, held securely within our Australian Azure environment, so your board's records can be restored in the event of a problem. Administrators can also export a full copy of your organisation's data at any time from the Backup & Export tools in the app.

Handling a security incident In place

If a data breach affecting personal information ever occurred, we would act to contain it promptly, assess whether it is likely to result in serious harm, and notify affected organisations without undue delay. We will comply with our obligations under the Notifiable Data Breaches (NDB) scheme administered by the Office of the Australian Information Commissioner (OAIC), including notifying the OAIC and affected individuals where the scheme requires it, and we'll give affected organisations a written summary of what happened and what we did about it.

Superadmin & staff access In place

BoardTable is operated by a very small team, and staff access to your data is limited to what's needed to run and support the service, under a principle of least privilege. The platform has a single superadmin role, held only by BoardTable's operators, which exists to provision new organisations and provide technical support. Superadmins are bound by confidentiality and will never read, disclose or act on the contents of your board's papers, minutes or registers except where strictly necessary to resolve a support request you've raised, or where required by law.

Reporting a security or privacy concern

If you believe you've found a security vulnerability, or you're concerned data may have been exposed or accessed improperly, email hello@boardtable.com.au with as much detail as you can safely share. We operate a responsible-disclosure approach, will acknowledge your report within 2 business days, and will keep you informed as we investigate. Please give us a reasonable opportunity to address an issue before disclosing it publicly.

Our security roadmap

We'd rather be honest about where we're headed than imply we're further along than we are. These are the security investments we're working towards — they are not in place yet:

What's coming

  • Application-managed encryption — a further layer of encryption on top of Azure's, with keys under our own control.
  • Independent penetration testing — engaging an external security firm to test the platform on a regular cycle.
  • SOC 2 Type II — establishing BoardTable's own controls programme and pursuing independent attestation across Security, Availability and Confidentiality.
  • A formal, documented incident-response plan — building on the obligations and practices described above.