Encryption at rest and in transit
The material is encrypted both where it is stored and as it moves between your browser and the service.
Strictboard is built with security as a core principle — not an afterthought.
We protect your board documents, contracts, and personal data with industry-leading technology and strict procedures.

Encrypted, access-controlled, and always logged.
Every part of Strictboard is designed to protect your data. From transport to storage — nothing is left unprotected.

Someone will want to know exactly this before the material moves in. The answers should exist before the question does.
Board material is among the most sensitive information a company holds: acquisition plans, personnel matters, financials before release and the basis for decisions not yet taken. It is reasonable for a director to ask where it goes.
Where is it stored? All data is stored and processed within the EU. This is the question that most often decides whether a procurement proceeds.
Who can reach what? Access is controlled per role — director, deputy, CEO, auditor and co-opted attendee. An auditor invited for year-end does not need to see personnel matters.
Can you see who did what? Every access and change is logged. That log is what gets asked for when a decision is challenged, and what makes it possible to show when material was shared and with whom.
What happens if we leave? You export everything at any time. On cancellation the data is securely deleted within 30 days. The data is yours, not ours.
Six mechanisms the board material rests on.
The material is encrypted both where it is stored and as it moves between your browser and the service.
Permissions follow the board role, not a generic account. A co-opted adviser sees their matter, not the whole archive.
Used for sign-in and for digitally signing minutes, and provides strong authentication for general meeting voting.
Access and changes are logged, so it can be shown afterwards who saw what, and when.
Documents are not overwritten. Every version is kept with its date, which is what makes the archive useful under review.
When a director leaves, permissions are withdrawn but the history stays. That is the difference from material that lived in an inbox.
Four things that sometimes appear on a vendor review and that we do not meet.
If any of them is a requirement for you, other vendors have them.
No ISO 27001 certification. We describe our actual safeguards openly instead. If certification is a formal requirement, look elsewhere.
No transaction data room. Facing a sale or due diligence, you will likely need a separate tool.
No inside information handling. If you are listed, insider list logging under the Market Abuse Regulation requires routines and tools outside a board portal.
No native mobile app. The tool is mobile-friendly in the browser, but there is no iOS or Android app.