Glass office door with lock representing controlled access.

Trust

Security and confidentiality for formal minutes work.

Boardmate sets out how customer environments, identity, reviewer access, AI processing, data flow and assurance work together.

01 Environment

Boardmate provisions a separate AWS-based environment in a supported AWS region selected for each customer.

02 Access

Named users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.

03 Review

Reviewer links can expire or be revoked, while comments, confirmations and decisions remain with the meeting.

Security

Security built around confidential board work.

Boardmate combines a separate AWS-based customer environment, named-user access, controlled review and a recorded decision trail. The security review follows the same path as the material.

Customer setup Select the AWS region, identity provider, named users and reviewer access for the workspace.
Security review

Current data-flow, supplier, retention, deletion and control information is available for customer review.

Customer environment

Boardmate provisions a separate AWS-based environment in a supported AWS region selected for each customer.

Identity

Named users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.

Controlled review

Reviewer access can expire or be revoked, while comments, confirmations and decisions stay with the meeting.

Assurance programme

Supported by Innovate UK, Boardmate is working towards ISO/IEC 27001:2022 certification.

01

Customer setup

The customer selects the AWS region and supplies the named users, roles and permissions required for the workspace.

Microsoft Entra ID can add user assignment and Conditional Access where the customer uses it.
02

Review and approval

Scoped reviewer links, comments, uploads, no-comment confirmations, revocations and chair decisions stay attached to the meeting record.

The chair or delegated owner decides what is accepted into the next version.
03

Independent assurance

Boardmate will complete independent application penetration testing and address any material findings before a client workspace goes live.

ISO 27001 certification is the next formal assurance milestone.

Trust detail

Private workspaces, revocable links, audit history, and security review detail.

Environment
Separate

An AWS-based customer environment for database, authentication, storage and server functions.

Identity
Named users

Microsoft, Google or Zoom sign-in, with MFA managed by the selected provider.

Review
Controlled

Scoped links, revocation, expiry and activity records for the relevant meeting.

Programme
ISO 27001

ISO/IEC 27001:2022 programme supported by Innovate UK, with independent application testing before live use.

Security categories

The security review conversation has a clear structure.

Separate customer environment

Boardmate provisions a separate AWS-based environment in a supported AWS region selected for each customer.

Named-user identity

Users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.

Controlled reviewer access

Review links can expire or be revoked, while comments, confirmations and decisions remain with the meeting.

Documented data flow

The current supplier schedule records each provider's role, data categories, processing location and published assurance.

Retention and deletion

Source files, drafts and final records follow the retention and deletion controls for the customer workspace.

Independent assurance

Application penetration testing and remediation of material findings will be completed before a client workspace goes live.

Customer environment and access

Boardmate provisions a separate AWS-based customer environment for the database, authentication, storage and server functions used for customer data. The environment can be provisioned in a supported AWS region selected for the customer.

Environment

Customer database, authentication, storage and server functions are separated from other customer environments.

Identity

Users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.

Microsoft

Microsoft Entra ID can add user assignment and Conditional Access where the customer uses it.

Reviewer links are controlled

Private review access is recipient-specific where possible, revocable, expiring, and auditable. A reviewer can read a draft, comment on a passage, upload support, or confirm no comments without becoming a full workspace user.

  • Workspace users manage source material, decisions, regeneration, export, and audit history.
  • Reviewers receive scoped access for the relevant draft and permitted actions.
  • Revocation, expiry, and activity history support a controlled review close.

Security programme and independent assurance

Supported by Innovate UK, Boardmate is building its information security management system in line with ISO/IEC 27001:2022. The programme covers risk management, supplier assurance, access control, secure development, incident response and continuity.

  • Before a client workspace goes live, Boardmate will complete independent application penetration testing and address any material findings.
  • ISO 27001 certification is the next formal assurance milestone.
  • Current data-flow, supplier, retention, access-control and implementation information is available for customer security review.

Common questions

Security questions teams ask.

Should confidential material be uploaded before security review is complete?

No. Real board packs, transcripts, recordings, draft minutes, and support files should wait until confidentiality and data-handling terms are agreed.

What can reviewers see through private links?

Reviewers see the draft and permitted support material for their review task. Workspace users keep control of source material, decisions, regeneration, export, and deletion requests.

What security detail can procurement request?

Teams can request current detail on data flow, subprocessors, access control, retention, deletion, support access, residency questions, and contract terms.