Customer setup
The customer selects the AWS region and supplies the named users, roles and permissions required for the workspace.
Microsoft Entra ID can add user assignment and Conditional Access where the customer uses it.
Trust
Boardmate sets out how customer environments, identity, reviewer access, AI processing, data flow and assurance work together.
Boardmate provisions a separate AWS-based environment in a supported AWS region selected for each customer.
Named users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.
Reviewer links can expire or be revoked, while comments, confirmations and decisions remain with the meeting.
Security
Boardmate combines a separate AWS-based customer environment, named-user access, controlled review and a recorded decision trail. The security review follows the same path as the material.
Current data-flow, supplier, retention, deletion and control information is available for customer review.
The customer selects the AWS region and supplies the named users, roles and permissions required for the workspace.
Microsoft Entra ID can add user assignment and Conditional Access where the customer uses it.Scoped reviewer links, comments, uploads, no-comment confirmations, revocations and chair decisions stay attached to the meeting record.
The chair or delegated owner decides what is accepted into the next version.Boardmate will complete independent application penetration testing and address any material findings before a client workspace goes live.
ISO 27001 certification is the next formal assurance milestone.Trust detail
An AWS-based customer environment for database, authentication, storage and server functions.
Microsoft, Google or Zoom sign-in, with MFA managed by the selected provider.
Scoped links, revocation, expiry and activity records for the relevant meeting.
ISO/IEC 27001:2022 programme supported by Innovate UK, with independent application testing before live use.
Security categories
Boardmate provisions a separate AWS-based environment in a supported AWS region selected for each customer.
Users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.
Review links can expire or be revoked, while comments, confirmations and decisions remain with the meeting.
The current supplier schedule records each provider's role, data categories, processing location and published assurance.
Source files, drafts and final records follow the retention and deletion controls for the customer workspace.
Application penetration testing and remediation of material findings will be completed before a client workspace goes live.
Boardmate provisions a separate AWS-based customer environment for the database, authentication, storage and server functions used for customer data. The environment can be provisioned in a supported AWS region selected for the customer.
Customer database, authentication, storage and server functions are separated from other customer environments.
Users can sign in through Microsoft, Google or Zoom. The selected provider manages MFA, including any enforcement policy.
Microsoft Entra ID can add user assignment and Conditional Access where the customer uses it.
Private review access is recipient-specific where possible, revocable, expiring, and auditable. A reviewer can read a draft, comment on a passage, upload support, or confirm no comments without becoming a full workspace user.
Supported by Innovate UK, Boardmate is building its information security management system in line with ISO/IEC 27001:2022. The programme covers risk management, supplier assurance, access control, secure development, incident response and continuity.
Common questions
No. Real board packs, transcripts, recordings, draft minutes, and support files should wait until confidentiality and data-handling terms are agreed.
Reviewers see the draft and permitted support material for their review task. Workspace users keep control of source material, decisions, regeneration, export, and deletion requests.
Teams can request current detail on data flow, subprocessors, access control, retention, deletion, support access, residency questions, and contract terms.