Security
How BoardFluent protects your data
BoardFluent is operated by Gulf Holdings LLC. Founders use it to prepare and share board and investor materials, so data protection is built into the product, not bolted on. Below is a plain-language overview of the controls in place today.
Confidential board-book delivery
Board book viewer links are issued per recipient and can be revoked at any time. Every PDF page carries the recipient email plus a forensic hash embedded in the document metadata, so a leaked copy can be traced back to the source recipient. Each view is recorded in a per-recipient audit log, and recipient links are origin-restricted and revocable.
How we protect your data in AI analysis
The GTM Diagnostic uses frontier AI to score nine go-to-market dimensions. Because the input is confidential operating data, we apply layered controls before anything reaches an AI provider.
De-identification before processing
We remove direct identifiers from your data in our systems before our AI analyzes and scores your company. Company names, people names, customer references, domains, and email addresses are replaced with internal tokens in our systems. The scoring and synthesis layers operate on those tokens, not the real values.
Per-engagement public-search control
Each diagnostic engagement has a public-search setting. When public search is off (the default for deal and third-party evaluation engagements), no discovery or enrichment call runs, and no real company identifier reaches the AI provider. When you run without public search, your company identity is never sent to or inferable by the AI. Operators may also use a project code name instead of the real company name, which is standard practice for pre-acquisition diligence.
When public search is enabled (the default for self-diagnosis engagements), outside-in research runs against public sources. The weaker, honest position applies: Company identifiers are tokenized before analysis. Because the diagnostic cites public sources, those sources may still reveal your identity.
Strict document handling
Uploaded documents are processed without sending their text to external AI providers. When a document (such as a board deck or CIM) is uploaded, our system extracts structured field values locally and de-identifies those values before they enter the pipeline. Raw document prose is not transmitted to any external AI provider by default. A model-assisted extraction fallback exists but is disabled by default and requires an explicit operator configuration flag.
Account and data deletion
You can permanently delete your account and all associated data from our systems (with limited legal and anonymized-aggregate exceptions). The deletion flow covers diagnostics and all child records, uploaded documents and storage objects, board books, API keys, embed tokens, and the de-identification token map (which is a re-identification key and is deleted with the engagement data it protects). The limited exceptions (anonymized benchmark aggregates you opted into, Stripe billing records retained by law, platform backup snapshots on a rolling purge schedule, and best-effort async deletion requests to PostHog and Sentry) are disclosed in the deletion confirmation dialog.
For security questionnaires or diligence reviews, contact security@boardfluent.com.
Imported financial data & benchmarks
Imported financial data (CSV uploads, plus authorized Stripe sync) is scoped to the operator who authorized it and is never shared across accounts. Cohort benchmarks are computed only on opted-in, anonymized inputs, see the Privacy Policy for details. Embed tokens are origin-restricted and revocable, so you control which sites may embed your calculators.
Infrastructure & subprocessors
BoardFluent is built on established cloud platforms, ultimately running on Amazon Web Services (AWS) data centers, and inherits their physical, network, and platform security controls. AWS facilities are independently audited against SOC 1/2/3, ISO 27001, and PCI DSS, and each provider below publishes its own security attestations on its trust pages. Our current subprocessors:
Amazon Web Services (AWS)
Underlying cloud data centers (US regions). Our database and application hosts run on AWS, whose facilities maintain SOC 1/2/3, ISO 27001, and PCI DSS certifications.
Supabase
Database, authentication, and storage, runs on AWS infrastructure
Vercel
Application hosting and compute, runs on AWS infrastructure
Stripe
Payment processing and read, only Connect data sync (PCI DSS Level 1)
Postmark
Transactional and board-book delivery email
PostHog
Product analytics
Sentry
Error monitoring and performance diagnostics
Anthropic
Large-language-model inference for the GTM Diagnostic
Google (Vercel AI Gateway)
Gemini large-language-model inference for AI-assisted board-book drafting
Service keys and other secrets run server-side only and are never exposed to the browser. Enterprise customers can request the current subprocessor list or a signed Data Processing Addendum, see the DPA.
Responsible disclosure
Found a vulnerability? Report it to security@boardfluent.com with enough detail to reproduce the issue. We review every report and will not pursue action against good-faith research that respects user privacy and avoids service disruption.
Related policies
See the Privacy Policy, Data Processing Addendum, and Acceptable Use Policy for how we collect, process, and retain data.