Trust
Security — where we stand today
Written for skeptical directors, counsel, and IT. We do not claim an audit, a certification, or a completed pen test before they are real. Prepared is an invite-only beta. Companion pages: /trust, /trust/ai, /procurement, /leaving-prepared.
Real now
- Role-based access control and DocumentACL on restricted materials
- Append-only audit log for access, votes, documents, and membership changes
- Password and Google sign-in, with optional two-factor sign-in (authenticator app, 10 hashed one-time recovery codes); a chair can require two-factor for every board member
- Uploaded PDFs are validated before storage: real PDF, 15 MiB limit, and no encryption, JavaScript, embedded files, launch or form-submit actions (validation, not antivirus scanning)
- Agent connection (off until the chair allows it): a director's own assistant reads through an MCP server / API (read-only plus drafting questions) via OAuth sign-in (PKCE, consent screen) or a personal access token — hashed, scoped, expiring, revocable — under the same access rules as the app; executive-session material is never sent to agents (directors read it in the app); every call audit-logged
- Database point-in-time restore (Neon), 6-hour window; restore drill run 2026-10-10 with matching row counts, restored copy queryable in ~4 seconds
- Hosting: Vercel (app hosting, US iad1) + Neon Postgres (database, AWS us-east-2) + Vercel Blob (uploaded files), with provider-managed encryption at rest and TLS in transit
- Full export and /leaving-prepared: the full record of decisions, votes, minutes, actions and document details; uploaded files download separately
- Per-board AI features off + honest /trust/ai policy (no foundation-model calls today)
- Per-board records policy: draft retention, legal hold, counsel-direction markings (marking ≠ privilege)
Not yet
- No independent security audit or certification yet
- Antivirus / malware scanning of uploads — not live (see validation above)
- Backups beyond the 6-hour database restore window, and point-in-time restore for uploaded files — not yet
- Outside / third-party penetration test — planned before paid launch
- Customer-managed encryption keys (BYOK / CMK) — roadmap
- Enterprise SSO (SAML / OIDC via WorkOS) — built; live once production credentials are connected and your email domain is mapped (Governance+, setup on request). SCIM directory sync is a stub — not live
- Stripe billing (checkout, customer portal, signed webhooks, plan gating) — built; live once production credentials are connected. Not yet run against a live Stripe account; nothing is charged today
Report a security problem
If you think you have found a security problem in Prepared Board, email security@preparedboard.com with what you found and the steps to see it. Please do not open, change, or keep anyone else's board information, and give us a fair chance to fix the problem before you share it. We read every report and reply to the address you write from. We do not run a paid bug bounty.
Planned path
- Publish this page + /trust + /trust/ai and keep them current
- Commission a third-party pen test before paid customer data
- Offer a security addendum on request (Procurement & IT)