Security

How BoardRepo protects private boards and files, and how to report a security issue.

Last reviewed: August 24, 2026

Summary

  • Private files are not publicly addressable, and access is checked before download.
  • Uploads are treated as untrusted and processed with safety and resource limits.
  • Sessions and connected-assistant access are scoped, time-limited, and revocable where applicable.
  • Production traffic uses HTTPS and standard browser security protections.
  • SOC 2 and ISO 27001 work is underway.

Security approach

This page describes how private links work, where files are stored, and which safeguards are currently in place.

We are working toward SOC 2 and ISO 27001. We will share updates here as that work progresses.

An unlisted project is absent from listings and marked noindex. Anyone with its URL can open the project, including when somebody forwards it. Add a password when the link alone should not provide access, or choose Private when the board should not leave your account at all.

BoardRepo checks access to the project page and its files. Opening a page does not bypass the checks applied to file downloads.

File storage and downloads

Original files and generated output are kept in private storage. BoardRepo checks each download request and may use temporary delivery links to serve a file.

Upload processing

We treat every upload as untrusted. Archives are screened before extraction, and conversion runs with limits on time, memory, file count, and output size.

Accounts and tokens

Credentials and session secrets are stored or handled using standard protections. Access grants are scoped to their purpose and expire where appropriate. A connected assistant only receives the access you approved, and you can revoke that connection in Settings.

Browser security controls

Production traffic uses HTTPS. Browser security headers limit common risks such as unwanted framing, content sniffing, excessive referrer details, and unnecessary browser permissions. We review and tighten these controls as BoardRepo changes.

Backups and monitoring

BoardRepo uses established infrastructure providers, keeps backups away from the primary database, and monitors the service for failures. Backup and recovery procedures are reviewed as the service grows.

What you can do

We cannot stop a recipient from forwarding a private link or keeping a file they already downloaded. Keep your sign-in account safe, revoke old assistant connections, and check visibility before publishing. Keep a local backup of important boards.

Report a security issue

Email [email protected] with the affected URL, reproduction steps, and likely impact. Use your own accounts and boards. Stop if you see another person's private data, and do not put secrets or board files in the opening email.

We do not currently offer a public bug bounty. Please allow reasonable time for us to investigate and address a report before publishing it. The machine-readable contact is /.well-known/security.txt.

Questions

For personal-data questions, use [email protected] or read the Privacy Policy.

Sign in to BoardRepo

New here? Signing in creates your account; there is no separate sign-up.