BoardLens Logo

BoardLens Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Welcome to BoardLens's Trust Center. BoardLens is an intelligence platform for directors, boards and portfolios, and safeguarding the confidential information our customers entrust to us is fundamental to everything we build.

Our platform runs on AWS in the European Union (Frankfurt), with data encrypted in transit and at rest, least-privilege access controls, and continuous security monitoring using enterprise-grade tooling. We operate in line with SOC 2 and GDPR.

Use this Trust Center to learn about our security posture and to request access to our policies and security documentation.

Documents

DOCUMENTSVAPT Certificate

Product Security

BoardLens is engineered security-first. Our platform enforces encryption in transit and at rest, least-privilege access with multi-factor authentication, and network segmentation across every layer. Secure development practices — reviewed pull requests, automated testing, and signed commits — govern every change we ship, and the environment is continuously monitored for threats. The Security Overview below summarizes these controls; deeper documentation is available on request.

Data Security

Customer data is encrypted in transit (TLS 1.2+) and at rest, hosted exclusively in the European Union (AWS, Frankfurt), and logically isolated so each customer's data remains separate and confidential. Access follows least-privilege principles with mandatory multi-factor authentication. Detailed documentation is available on request.

AI

AI is core to BoardLens, and we hold it to the same standard as the rest of our security program. Your data is never used to train AI models. We maintain enterprise agreements and Data Processing Agreements with every underlying AI provider, and each customer's content stays within its own isolated workspace. Further detail is available on request.

Data Privacy

BoardLens is built for GDPR. Customer data is hosted in the EU, processed under a Data Processing Agreement available on request, and we support data-subject rights. We never sell customer data or use it for any purpose beyond delivering the service.

Access Control

Access to production systems is governed by least-privilege controls with mandatory multi-factor authentication, and is provisioned and revoked through a documented joiner–mover–leaver process. Access is logged and reviewed. Details available on request.

Infrastructure

BoardLens runs on Amazon Web Services in the European Union (Frankfurt), with encryption at rest and in transit, segmented networking, and continuous monitoring via Amazon GuardDuty, AWS CloudTrail, and Amazon CloudWatch. Details available on request.

Policies

BoardLens maintains a complete set of security and privacy policies — including Information Security, Access Control, Encryption, Change Management, Incident Response, Business Continuity & Disaster Recovery, Data Retention, and Vulnerability Management — reviewed at least annually. These are available on request.

Incident Response

BoardLens maintains a documented incident response process covering detection, containment, remediation, and customer notification where applicable. Details available on request.

Risk Management

BoardLens runs a documented risk-management process, including regular risk assessments and supply-chain / vendor risk review, with mitigations tracked to closure. Details available on request.

Asset Management

BoardLens maintains an inventory and classification of its information assets to ensure they are tracked, owned, and protected throughout their lifecycle. Details available on request.

BC/DR

BoardLens maintains a business continuity and disaster recovery plan, supported by automated, encrypted backups, to keep the service resilient and recoverable. Details available on request.

Change Management

Changes to BoardLens's production systems follow a documented change-management process: all changes are version-controlled and merged via reviewed pull requests, with automated tests, required status checks, and signed commits, and can be rolled back if needed. Details available on request.

Continuous Monitoring

BoardLens continuously monitors its AWS environment for threats and vulnerabilities using automated tooling — including Amazon GuardDuty, AWS CloudTrail, and CloudWatch alarms — with alerting on anomalous activity. Details available on request.

Knowledge Base (FAQ)
  • Do you have an incident response process?
  • Do you back up data?
  • How do you handle staff offboarding?
  • Who can see my data?
  • How do you control access to systems?
View more
If you need help using this BoardLens Trust Center, please contact us.
Contact support