Security and Information Governance Overview
Last updated: 30 August 2026
1. Scope
This document describes the current security and information-governance position without claiming certifications or controls that have not been verified.
2. Data classification and intended use
BoardCue is designed for confidential corporate governance information across sectors. It is not intended to replace sector-specific operational systems or to act as the primary repository for routine individual case-management records. Governance material should use aggregated, anonymised, summarised or otherwise appropriately governed information where practical, while recognising that sensitive workforce, incident, complaint, safeguarding or other case-related information may legitimately appear in board and committee papers.
3. Hosting and data location
The production Supabase project, including its primary database and document storage, is hosted in the United Kingdom. Enterprise deployments are to use Supabase Pro or higher under the current assurance baseline. Supabase publishes automatic daily database backups with the last 7 days available on Pro.
4. Identity, access and MFA
Authenticated user access through Supabase-backed identity controls.
Organisation owners/admins can require MFA for organisation users.
Role and committee access controls restrict governance content by intended membership.
Row-level database access controls support tenant separation.
Privileged operations use stronger authentication controls in relevant routes.
Server-side AAL2 enforcement hardening for all protected organisation operations is an identified assurance improvement.
5. AI security and governance
Cloud AI requests are initiated through authenticated BoardCue server functions and routed through the direct Google Cloud Vertex AI and OpenAI API services. Provider/model selection is controlled server-side. Exact AI provider processing geography, logging, retention and downstream provider account controls remain subject to written vendor confirmation.
BoardCue is designed to distinguish evidence from AI interpretation and retain human responsibility for governance judgement.
6. Browser transcription
Managed Live Board transcription uses browser/OS speech recognition. The customer organisation is responsible for approving and configuring its endpoint/browser environment. ADEPTABLE does not control or warrant how the third-party browser/OS provider processes speech audio. BoardCue stores the transcript text returned to the application according to the customer's governance lifecycle.
7. Email and attachments
Resend is used for outbound transactional email and Postmark for inbound intelligence email. Inbound attachments enter quarantine and the scanning integration is fail-closed if the required malware scanning configuration is absent. The production malware scanning provider must be verified before being listed as an active subprocessor.
8. Support access
Support access is designed to require explicit customer authorisation, be time-limited, revocable and audited, and be read-only by default. Exceptional write-capable support must use additional controls and be necessary to resolve the relevant issue.
9. Deletion and exit
The revised exit design provides a full organisation export, a 14-day read-only download window and deterministic deletion. This is an implementation gate and should not be represented as fully operational until engineering verification is complete.
10. Incident management
ADEPTABLE's processor breach-notification rule is awareness-based: notification without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with a 24-hour operational target where practicable. Initial notification can be followed by phased updates.
11. Current assurance status
| Area | Status |
|---|---|
| Cyber Essentials | Not currently claimed. Planned assurance programme item. |
| Independent penetration test | Not currently claimed. Required before large-scale enterprise rollout. |
| ISO 27001 / SOC 2 | Not claimed by ADEPTABLE. Supplier certifications may be referenced only as supplier evidence. |
| Sector-specific assurance | Not treated as evidence that BoardCue processes individual case records. Maintain supplier-position statement and complete if a customer/procurement requires it. |
| Sector-specific technology assurance | Maintain readiness mapping where relevant; not represented as a universal product certification. |
| Sector-specific safety standard | Current governance intended use is provisionally outside operational case-management Health IT scope; reassess if product use changes materially. |
| Availability SLA | 99.5% draft target only. Do not activate contractually until health monitoring can calculate monthly Core Platform Availability. |

