Security & Trust

Built for how funds
actually handle deal data.

Portfolio deal data is material non-public information. OperatorBoard is architected from the ground up to keep it isolated, access-controlled, and auditable, without trading convenience for security.

What's true today

Six guarantees, in production now.

These are architectural facts about how OperatorBoard works today, not aspirational claims. Where a guarantee has an edge, the edge is written into the sentence.

Per-fund data isolation

Every fund's workspace is row-level-security scoped at the Postgres level via Supabase RLS. One firm's deal data is structurally unreachable by any other fund, not just by policy but by database enforcement.

We never train on your data

AI features make a stateless per-request call to a hosted model (Anthropic's Claude, routed through OpenRouter). OperatorBoard writes no prompt and no completion to its database, ships no training set, and runs no fine-tuning on your content. Retention on the provider side is governed by their API terms, which we will walk your team through.

Role-based access control

Board, operator, and portfolio-owner roles each receive a scoped view. Board members see the rollup. Portfolio operators see their companies. Admins manage the workspace. No role can elevate its own permissions.

Versioned audit trail

Every thesis sign-off and monthly-report approval is timestamped and attributed to the user who took the action. The record is immutable: who approved what, and when.

Encryption in transit and at rest

All data travels over TLS 1.3. Data at rest, including automated backups, is encrypted with AES-256 by Supabase's managed Postgres layer. Disk encryption is where that protection stops: an authorised session still reads live rows, which is why the isolation and role scoping above do the access-control work.

Google Workspace or email sign-in

Authentication runs on Supabase Auth. Your team can sign in with a Google Workspace account, or with email and a password. Passwords are hashed and held by Supabase Auth in the managed auth schema, which is not exposed through the application's API and which OperatorBoard's own tables never join to. Every request revalidates the session against the auth server instead of trusting the cookie.

AI architecture

Your thesis is not a training dataset.

When OperatorBoard drafts a board deck or summarises a variance, it makes a stateless API call to a hosted language model. There is no session and no conversation history. The prompt carries only the ledger lines the current request needs, and neither the prompt nor the answer is written back to our database.

What happens on the far side of that call is the model provider's contract, not our architecture, and we are not going to describe it as if it were ours. The request passes through OpenRouter to Anthropic, and retention there is set by their API terms. If your vendor policy requires zero data retention in writing across both hops, ask us: we will show you the current account configuration and the state of that agreement before you sign anything.

Model provider
Claude (Anthropic), routed via OpenRouter
Request type
Stateless. No session, no history
Prompt includes
Only the ledger lines for the current request
Retained by OperatorBoard
Nothing. No prompt or completion is stored
Retained by provider
Set by OpenRouter and Anthropic API terms. Ask us for the current configuration
Used for training
Never by us. API access only, no fine-tuning
Zero-retention agreement
On the roadmap below, not signed today

On the roadmap

Coming for enterprise funds.

These capabilities are committed on the roadmap and are not live today. We will not claim otherwise.

Roadmap

Enterprise SSO / SAML

Okta, Azure AD, and any SAML 2.0 provider, so your IT team controls provisioning and deprovisioning.

Roadmap

Configurable data retention

Set workspace-level retention windows so data is automatically purged when your policy requires it.

Roadmap

Exportable audit logs

Machine-readable export of all sign-offs, approvals, and user actions for your own compliance archive.

Roadmap

Contracted zero retention

A signed zero-data-retention agreement covering both the gateway and the model provider, so retention is contractual rather than a setting we hold.

Honest disclosure

What we are not (yet) certified for

OperatorBoard is not currently SOC 2 Type II certified, ISO 27001 certified, or FedRAMP authorized. If those certifications are required for your fund's vendor policy, contact us. We will tell you exactly where we are in the process and whether the timeline fits your diligence window.

We believe the architectural guarantees above are more meaningful for a fund-stage deployment than checkbox certifications applied to a general-purpose SaaS product. We will pursue them as the right stage arrives.

Ready to carry the thesis to exit?

Free while OperatorBoard is in preview. Full platform.