Security and Information Governance Overview

Last updated: 30 August 2026

Status: Enterprise assurance draftDownload approved document (PDF)

1. Scope

This document describes the current security and information-governance position without claiming certifications or controls that have not been verified.

2. Data classification and intended use

BoardCue is designed for confidential corporate governance information across sectors. It is not intended to replace sector-specific operational systems or to act as the primary repository for routine individual case-management records. Governance material should use aggregated, anonymised, summarised or otherwise appropriately governed information where practical, while recognising that sensitive workforce, incident, complaint, safeguarding or other case-related information may legitimately appear in board and committee papers.

3. Hosting and data location

The production Supabase project, including its primary database and document storage, is hosted in the United Kingdom. Enterprise deployments are to use Supabase Pro or higher under the current assurance baseline. Supabase publishes automatic daily database backups with the last 7 days available on Pro.

4. Identity, access and MFA

Authenticated user access through Supabase-backed identity controls.

Organisation owners/admins can require MFA for organisation users.

Role and committee access controls restrict governance content by intended membership.

Row-level database access controls support tenant separation.

Privileged operations use stronger authentication controls in relevant routes.

Server-side AAL2 enforcement hardening for all protected organisation operations is an identified assurance improvement.

5. AI security and governance

Cloud AI requests are initiated through authenticated BoardCue server functions and routed through the direct Google Cloud Vertex AI and OpenAI API services. Provider/model selection is controlled server-side. Exact AI provider processing geography, logging, retention and downstream provider account controls remain subject to written vendor confirmation.

BoardCue is designed to distinguish evidence from AI interpretation and retain human responsibility for governance judgement.

6. Browser transcription

Managed Live Board transcription uses browser/OS speech recognition. The customer organisation is responsible for approving and configuring its endpoint/browser environment. ADEPTABLE does not control or warrant how the third-party browser/OS provider processes speech audio. BoardCue stores the transcript text returned to the application according to the customer's governance lifecycle.

7. Email and attachments

Resend is used for outbound transactional email and Postmark for inbound intelligence email. Inbound attachments enter quarantine and the scanning integration is fail-closed if the required malware scanning configuration is absent. The production malware scanning provider must be verified before being listed as an active subprocessor.

8. Support access

Support access is designed to require explicit customer authorisation, be time-limited, revocable and audited, and be read-only by default. Exceptional write-capable support must use additional controls and be necessary to resolve the relevant issue.

9. Deletion and exit

The revised exit design provides a full organisation export, a 14-day read-only download window and deterministic deletion. This is an implementation gate and should not be represented as fully operational until engineering verification is complete.

10. Incident management

ADEPTABLE's processor breach-notification rule is awareness-based: notification without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with a 24-hour operational target where practicable. Initial notification can be followed by phased updates.

11. Current assurance status

AreaStatus
Cyber EssentialsNot currently claimed. Planned assurance programme item.
Independent penetration testNot currently claimed. Required before large-scale enterprise rollout.
ISO 27001 / SOC 2Not claimed by ADEPTABLE. Supplier certifications may be referenced only as supplier evidence.
Sector-specific assuranceNot treated as evidence that BoardCue processes individual case records. Maintain supplier-position statement and complete if a customer/procurement requires it.
Sector-specific technology assuranceMaintain readiness mapping where relevant; not represented as a universal product certification.
Sector-specific safety standardCurrent governance intended use is provisionally outside operational case-management Health IT scope; reassess if product use changes materially.
Availability SLA99.5% draft target only. Do not activate contractually until health monitoring can calculate monthly Core Platform Availability.