Security & Trust
Built for how funds
actually handle deal data.
Portfolio deal data is material non-public information. OperatorBoard is architected from the ground up to keep it isolated, access-controlled, and auditable, without trading convenience for security.
What's true today
Six guarantees, in production now.
These are architectural facts about how OperatorBoard works today, not aspirational claims. Where a guarantee has an edge, the edge is written into the sentence.
Per-fund data isolation
Every fund's workspace is row-level-security scoped at the Postgres level via Supabase RLS. One firm's deal data is structurally unreachable by any other fund, not just by policy but by database enforcement.
We never train on your data
AI features make a stateless per-request call to a hosted model (Anthropic's Claude, routed through OpenRouter). OperatorBoard writes no prompt and no completion to its database, ships no training set, and runs no fine-tuning on your content. Retention on the provider side is governed by their API terms, which we will walk your team through.
Role-based access control
Board, operator, and portfolio-owner roles each receive a scoped view. Board members see the rollup. Portfolio operators see their companies. Admins manage the workspace. No role can elevate its own permissions.
Versioned audit trail
Every thesis sign-off and monthly-report approval is timestamped and attributed to the user who took the action. The record is immutable: who approved what, and when.
Encryption in transit and at rest
All data travels over TLS 1.3. Data at rest, including automated backups, is encrypted with AES-256 by Supabase's managed Postgres layer. Disk encryption is where that protection stops: an authorised session still reads live rows, which is why the isolation and role scoping above do the access-control work.
Google Workspace or email sign-in
Authentication runs on Supabase Auth. Your team can sign in with a Google Workspace account, or with email and a password. Passwords are hashed and held by Supabase Auth in the managed auth schema, which is not exposed through the application's API and which OperatorBoard's own tables never join to. Every request revalidates the session against the auth server instead of trusting the cookie.
AI architecture
Your thesis is not a training dataset.
When OperatorBoard drafts a board deck or summarises a variance, it makes a stateless API call to a hosted language model. There is no session and no conversation history. The prompt carries only the ledger lines the current request needs, and neither the prompt nor the answer is written back to our database.
What happens on the far side of that call is the model provider's contract, not our architecture, and we are not going to describe it as if it were ours. The request passes through OpenRouter to Anthropic, and retention there is set by their API terms. If your vendor policy requires zero data retention in writing across both hops, ask us: we will show you the current account configuration and the state of that agreement before you sign anything.
On the roadmap
Coming for enterprise funds.
These capabilities are committed on the roadmap and are not live today. We will not claim otherwise.
Roadmap
Enterprise SSO / SAML
Okta, Azure AD, and any SAML 2.0 provider, so your IT team controls provisioning and deprovisioning.
Roadmap
Configurable data retention
Set workspace-level retention windows so data is automatically purged when your policy requires it.
Roadmap
Exportable audit logs
Machine-readable export of all sign-offs, approvals, and user actions for your own compliance archive.
Roadmap
Contracted zero retention
A signed zero-data-retention agreement covering both the gateway and the model provider, so retention is contractual rather than a setting we hold.
What we are not (yet) certified for
OperatorBoard is not currently SOC 2 Type II certified, ISO 27001 certified, or FedRAMP authorized. If those certifications are required for your fund's vendor policy, contact us. We will tell you exactly where we are in the process and whether the timeline fits your diligence window.
We believe the architectural guarantees above are more meaningful for a fund-stage deployment than checkbox certifications applied to a general-purpose SaaS product. We will pursue them as the right stage arrives.
Ready to carry the thesis to exit?
Free while OperatorBoard is in preview. Full platform.