An honest picture of where BoardHasA stands on certifications and regulatory frameworks today. We're an early-stage product without formal certifications yet — this page says so plainly rather than implying otherwise.
We do not currently hold SOC 2, ISO 27001, or any other third-party security or compliance certification, and we have not commissioned an external audit. We're not claiming alignment with these frameworks either — that's a real body of work we haven't done yet. If a certification becomes something our customers need, we'll pursue it and update this page when it's actually true.
If you're in the EU/UK and use BoardHasA, we act as a data processor for the personal data you or your team upload. We do not yet have a formal Data Processing Addendum, Standard Contractual Clauses, or an appointed EU representative under Article 27 — these are gaps we know about, not things we're claiming to have. We host data in a single region today rather than offering region-pinned storage.
If you need a DPA in place before you can use the Service, email us — we can put something reasonable together on request even though it isn't a productized, self-serve flow yet.
We don't sell or share personal information in the sense defined by the CCPA. If you're a California resident and want to know what data we hold about you, or want it corrected or deleted, email info@boardhasa.name and we'll handle it directly — we don't yet have a dedicated self-service portal or automated verifiable-request workflow.
We do not offer Business Associate Agreements and the Service is not currently built or reviewed for handling protected health information. If you're in healthcare, please don't upload PHI to BoardHasA today.
We don't currently process card payments through the product, so there's no cardholder data flowing through our systems to describe here. If and when we add billing, we'll use a PCI-compliant payment processor and update this page with real detail rather than boilerplate.
Application data and uploaded files are hosted with our infrastructure providers, including Cloudflare (object storage). We do not currently offer a choice of storage region — everyone's data is hosted in the same location today.
The vendors that currently touch customer data or communications, as best we can describe them today:
We don't yet run a formal 30-day advance-notice process for subprocessor changes — if that's a requirement for you, tell us and we'll work it out directly.
We don't have a standing customer-audit program or a pre-filled SIG/CAIQ/VSA on hand today. If you send us a security questionnaire, we'll answer it honestly and as promptly as we can — we're a small team, so please build in some lead time.
We'll update this page as our actual posture changes — new subprocessors, new certifications, new regions — rather than describing where we intend to be. The date at the top reflects the most recent update.
For compliance, audit, or procurement questions:
BoardHasA
info@boardhasa.name
Happy to walk through any of this directly, particularly for procurement or security reviews.