Board data is some of the most sensitive there is, and we protect it accordingly
We’re asked about our security approach regularly. As a rule we don’t expose detailed information about our security program, we don’t want to provide intelligence to bad actors. But our customers need to know that board data is protected by a best-practice program, so we’ve outlined the measures we take at a high level.
Data centre security
- We leverage Microsoft Azure to provide the infrastructure services that host our environment.
- By using Azure, BoardOutlook takes advantage of a sophisticated security environment, logging, identity and intrusion protection systems, so we can focus on our software and your data.
- Azure has a robust DDoS team constantly monitoring their data centres.
- We maintain a developed crisis management plan and disaster recovery plan to ensure continuity in the event of a large-scale disaster.
Application-level security
- We offer two-factor authentication (2FA), password sophistication controls and access-control restrictions to manage account access.
- BoardOutlook routinely scans its applications for vulnerabilities and security issues, and we promptly remediate anything we find.
- We encrypt with SSL, HTTPS and TLS.
- We employ multiple layers of encryption and obfuscation, designed to protect client data and privacy under all circumstances.
- We use a third party to conduct internal and external penetration testing to validate our perimeter and internal defensive posture annually.
Have a security question?
Our team is happy to walk your risk and IT stakeholders through our approach.
+61 1300 933 196 (AU) · +44 330 818 7746 (UK)