Security
Board Document Security
BoardCloud's document storage employs the AES-256 bit security specification. All documents stored on our servers are encrypted, including uploaded documents, platform-originated documents, and ancillary files such as cover pages and board packet divider pages.
No source documents are ever stored on a BoardCloud board portal.
Uploaded documents are encrypted as they are transferred, after which the source documents are deleted. All requests to open, view or edit a document are authenticated based on the Group and Role permissions of the requesting user, before being unencrypted for reading purposes.
Board Packet Security Options
All published packets and minutes are stored in encrypted form and can have additional security applied. These extra permissions are related to Adobe's PDF specifications.
Some commonly used extra security options include:
- Prevent printing of the document
- Password protect the document
- Prevent editing
The image below shows the plethora of BoardCloud security options that can be applied to each published board packet.

System Security
To begin with, the BoardCloud multi-tenant platform is built on the Microsoft Enterprise Framework. We make use of the latest built-in security features to ensure that your private company documents can only be accessed by authorized individuals.
Group & Role Based Security
Board packs are published to specific committees and are only visible to individual committee members once they have successfully logged in.
Audit Logs
All activity related to access of the board portal and the information it holds and protects are logged. Audit records contain dates, times and user information, as well as user actions. This information is available for forensic or routine audit purposes.
Sharing of Document Links
Documents stored in BoardCloud cannot be shared by simply emailing or messaging a link. When received by any of these means, clicking on a link will initiate a challenge/response process that requires the user to authenticate before the link is opened.
Document links are 'hashed' to make them impossible to guess or hack.
Click the link below to see an example of a link, which was too long to fit on this page!
Here's an example link:
Changing any character in the link above will invalidate it. Only authenticated users will be able to view it, provided they have the correct login and committee access roles.
IT Administrator Access
Often, secure document storage doesn’t go far enough. While users and unauthorized actors may be blocked from accessing documents on a server, system administrators often retain full access. In many cases, there’s nothing stopping a sysadmin from copying documents to a local drive in a readable format
With BoardCloud, this kind of transgression is not possible. Since the documents are stored with encrypted names and content. This renders them useless to bad actors looking for sensitive company information.
Optional Two-Factor Authentication (2FA)
Two Factor authentication adds an additional security level during the member login process. In BoardCloud, 2FA security for member logins is optional. It needs to be turned-on in your member profile.
You can read more about setting up 2FA in Help Admin - Edit Member Details Enabling 2-Factor Authentication
Once 2FA is enabled, a member logging in will be presented with an additional screen that will appear after successful entry of a username and password. The screen will look similar to the below image:

 
                    

