A compliance tool should be held to the standard it helps you meet. This page describes how Fresh Cut Boards is built and run today — including what we don't offer yet. It's a description, not a certification; our commitments are in the Terms and Data Processing Addendum.
1.Infrastructure
- The application runs in the United States on Vercel (requests pass through Vercel's global edge network), with the database and private file storage on Supabase (AWS us-east-1). See Subprocessors.
- Traffic between your browser, the service and our providers is encrypted with TLS; data is encrypted at rest by our database and storage provider.
- Daily managed database backups, kept up to 7 days.
- Production access is limited to authorized personnel; development tools and AI assistants are not used to read customer data.
2.Access control inside the product
- Every organization is isolated; every record is scoped to its organization on the server.
- Security groups — Admin, Contributor, Evidence gatherer, Document viewer, Auditor — decide what each person can see and do, and every action is checked on the server, not just hidden in the interface.
- Owners can never be locked out, nobody can change their own access, and access changes are recorded.
- Company email domains must be proven with a DNS record before anyone can join through them; admins choose invite-only, request-to-join or auto-join, and are emailed when someone joins.
- Files are private and served only through short-lived signed links after a permission check.
3.Sign-in
- Single-use email sign-in links that expire after 24 hours, with rate limits against abuse; sessions last 12 hours.
- No passwords are stored. Microsoft and Google sign-in are on the way.
4.Audit trail
Every create, update, delete, access change and vendor portal submission is written to an audit log that auditors in your organization can review and export. An automated check in our build keeps it that way.
5.How we build it
Changes are reviewed and tested before release, including checks that each permission is enforced on the server. We keep a written record of every defect and security finding, its fix and the test that guards against its return.
6.What we don't offer yet
- HIPAA Business Associate Agreements. Don't store protected health information in Fresh Cut Boards. Use it to run your HIPAA program and reference PHI held in BAA-covered systems.
- Our own SOC 2 report or ISO 27001 certification. We'll publish it here when we have one, and answer your security questionnaire in the meantime.
- Single sign-on and SCIM provisioning. Planned.
7.Reporting a vulnerability
Email security@freshcutboards.com with details and steps to reproduce. Please give us reasonable time to fix the issue before disclosing it, don't access or change other people's data, and don't degrade the service. Good-faith research that follows these guidelines is welcome, and we won't pursue legal action over it.