Trust Center
Security, privacy, and compliance — written for counsel and IT
How Prepared Board protects board materials, enforces access, and what is and isn't certified — in plain language.
Prepared Board has not had an independent security audit and holds no security certification. There is no auditor's report to share. Status last updated October 2026.
Security practices
Access control, compartments, and audit ship as product — not brochure copy.
Encryption at rest
Role-based access & compartments
Audit logs
Offboarding & remote wipe
Watermarking
Portable archive export
AI no-train default
Independent audit status
No independent security audit or certification yet. No outside firm has examined Prepared Board's controls, and we do not have an auditor's report or certificate to share. The controls described on this page are ones we built and describe ourselves.
Security review questions
For security questionnaires or architecture questions, contact security@preparedboard.com.
AI use — what we do / don’t
Prepared Board AI Data Use Policy
Prepared Board does not use Customer Content to train, fine-tune, or improve generalized machine learning or foundation models.
Today, Change Briefs, Decision Briefs, and draft minutes are composed from structured board data in the product — not from a foundation-model call. Optional generative AI features are not available yet. If or when an Organization enables optional AI, prompts and retrieved context would be processed solely to provide that feature to that Organization, under the same access controls and compartment rules as the underlying board materials. Privileged or vault-held content would be excluded from AI unless the Organization explicitly configures an allowed exception.
We do not sell Customer Content. Any subprocessors providing AI infrastructure may process data only under written agreements that prohibit training on Customer Content.
Organizations may disable AI features at any time. Any AI or structured drafts remain suggestions — humans approve anything that becomes official record.
Short line: Customer content is never used to train AI models.
Retention & export
Lock-in should be decision quality, not captivity. See /leaving-prepared for the full-record ZIP at /app/export.
Full-record ZIP
Owner, Admin, or Chair downloads prepared-board-record-export-v1 from /app/export: README, manifest, record.json, CSVs, and minutes Markdown. Document bodies, evaluation responses, and secrets are not included.
Board JSON archive
Smaller single-board JSON from the signed-in Trust Center: meetings, decisions, votes, actions, audit events, and document metadata with short previews. Uploaded files are not included.
After you leave
Export while active; 90-day post-cancellation window; cold archive on request for 12 months (storage fee only if retained beyond — disclosed). We do not wipe official records to force renewal.
Agent collaboration
Boards may bring an outside agent their own way. Prepared does not call any AI model. Directors can paste context into their own assistant, or — when the chair allows it — connect that assistant to an MCP server (read-only plus drafting questions) with a personal access token that never sees more than the director sees, with every call audit-logged. Executive-session material is never sent to agents; directors read it in the app.
What is live
Signed-in Copy for your agent on a decision or meeting (pasteable markdown), and published pack plain-text at /pack/{token}/agent; agent connection (MCP server + read-only API, off by default per board): /agents/connect. How-to: /agents.
What is not live
WebAuthn/passkeys, SCIM, and BYOK are not live, and there is no independent security audit or certification yet. Stripe billing and SAML/OIDC SSO are built; live once production credentials are connected. Cite /facts before trusting a summary.
Infrastructure & subprocessors
Invite-only beta. Named vendors below are the ones in use today; categories without a vendor name are not connected. We'll update this table before adding a new subprocessor.
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | App hosting and private file storage for uploaded PDFs (Vercel Blob, private access; files are served only through the app after an access check) | US (iad1) |
| Vercel Web Analytics & Speed Insights | Cookieless, aggregate site analytics and performance. Public pages send the page path; signed-in app and private links send only a normalized route pattern (IDs and tokens replaced, no query strings, no titles or names). Named funnel events carry no personal, board, or document identifiers | Vercel (aggregate) |
| Neon | Managed Postgres database | US (AWS us-east-2) |
| Resend | Transactional email: password reset, email verification, invites and reminders. Delivery is reported only when Resend accepts the send | US (us-east-1) |
| Google (sign-in) | Optional "Continue with Google" sign-in for existing accounts; we receive your name and verified email address only | Per provider |
| Auth providers | Password sign-in and Google sign-in today; Microsoft sign-in when configured; enterprise SSO (SAML/OIDC via WorkOS) built, not live until production credentials are connected; SSO / passkeys roadmap for live use | Per provider |
| Payments (Stripe) | Subscription checkout, customer portal, invoices — built, not live until production credentials are connected; card data stays with Stripe | Named when connected |
| AI infrastructure | Optional AI when offered (not available yet); structured briefs & minutes drafts today are composed from board data, not a foundation model | Contractual no-train if/when AI is enabled |
List last reviewed September 2026. DPA and SCCs available on request.
For security reviews
Questionnaire answer summary
Short answers for your security questionnaire, with what is available today kept separate from what is not.
| Topic | Today | Roadmap |
|---|---|---|
| Encryption at rest | Provider-managed encryption at rest from Neon (database) and Vercel Blob (uploaded files); TLS in transit | CMK/BYOK and envelope DEKs are intent, not live controls |
| SSO / MFA | Password sign-in and Google sign-in today (Google links only to an existing account with the same Google-verified email; it never creates accounts); password reset and email verification by email; two-factor sign-in with an authenticator app (TOTP) with 10 hashed one-time recovery codes, and a chair/owner setting to require it for every board member; session kill on revoke. SAML/OIDC SSO via WorkOS is built (existing memberships only, never grants admin, every login audited) and live once production credentials are connected | Live SAML/OIDC (IdP MFA), SCIM, passkeys |
| Access control | Role-based access enforced on every request; executive/privileged compartments; restricted items are invisible to anyone without access | Step-up auth for Counsel / executive-session downloads |
| Audit logging | Append-only events; CSV/JSON export; no delete path | SIEM stream; WORM option |
| Data residency | US hosting (Vercel iad1, Neon AWS us-east-2); no residency choice | Per-tenant residency picker |
| Subprocessors | Named above; DPA on request | Quarterly updates; customer notice per DPA |
| Incident response | Notify without undue delay; ≤72h where required | Tabletop evidence under NDA |
| Backup / DR | Neon point-in-time restore, 6-hour window (current plan maximum). Restore drill 2026-10-10: exact-timestamp copy matched every table's row count; queryable in ~4 s; RPO inside the window ≈ 0. Older than 6 hours is not restorable; uploaded files have no point-in-time restore | Longer restore window; off-provider database and file backups |
| Independent audit / pen test | No independent security audit or certification yet; no outside pen test yet | Outside pen test planned before paid launch (see /security) |
| AI data use | No-train on Customer Content; AI opt-in when offered | Provider zero-retention where available |
| Employee access | Policy intent: no standing staff access to board packs; no formal access-review process yet | Customer-visible break-glass log |
| Offboarding | Revoke kills sessions + ACL within one request cycle | SCIM deprovisioning; remote wipe for managed endpoints |
| Export / portability | Export at /app/export (Owner/Admin/Chair) + single-board JSON archive: the full record of decisions, votes, minutes, actions and document details; uploaded files download separately; /leaving-prepared; audited | Legal-hold export packages |
| Agent collaboration | Copy for your agent + pack /agent context; director-owned agent connection via MCP server / API (read-only plus drafting questions) with OAuth sign-in (PKCE) for Claude.ai / ChatGPT connectors or personal access tokens — hashed, scoped, expiring, revocable — off until the chair allows it, same access rules as the app, every call audit-logged. Prepared calls no AI model | Per-board connector allowlists |
Full answer bank for sales
Detailed paste-ready answers (SIG/CAIQ style) live in the internal GTM pack: gtm/SECURITY-QUESTIONNAIRE-ANSWERS.md. For NDA questionnaires, contact security@preparedboard.com.
Incident response
We notify affected customers without undue delay — and within 72 hours where legally required. Coordinated disclosure welcome at security@preparedboard.com.
Privacy & terms
The privacy and terms pages are drafts pending counsel review. We list subprocessors above and can discuss a DPA and any applicable transfer terms on request. We process director PII to operate the board OS — not to sell it.
Questions from counsel or IT?
Signed-in boards also see a live audit log under /app/trust.