01
Access control
Start with who can access what. Board materials often need more than a single private workspace: directors, executives, assistants, committee members, observers, and guests may each need different permissions.
A secure board portal should let administrators change access without moving files between folders or rebuilding the whole board pack.
- Role-based access for directors, executives, and observers
- Committee-specific spaces and meeting records
- Agenda-item or document-level restrictions
- Revocation after circulation
- Clear handling for conflicts and recusals
| RFP question | Yes/No | Evidence to request |
|---|---|---|
| Can access be limited by board role, committee, observer status, and meeting? | Yes/No | Live demo with one director, one observer, and one committee-only paper |
| Can access be revoked after board-pack circulation? | Yes/No | Audit export showing revoke event and resulting access state |
| Can the portal show who opened or downloaded a sensitive paper? | Yes/No | Meeting-level audit report for one document and one user |
| Can former directors be offboarded without losing historical records? | Yes/No | Offboarding workflow and retained record example |
Where BoardKite helps
BoardKite supports granular organization and meeting roles so access can follow the governance context instead of a generic folder structure.
02
Encryption and data protection
Encryption should cover data in transit and at rest. For board portals, the more important question is scope: which records are encrypted, how keys are managed, and whether sensitive workflows share the same protection.
Ask vendors whether agendas, minutes, transcripts, decisions, and attachments are all covered, not just uploaded files.
- TLS for traffic in transit
- Encryption at rest for stored records
- Clear key-management model
- Protected transcripts and AI-generated drafts
- Documented backup and recovery posture
Where BoardKite helps
BoardKite encrypts agendas, minutes, transcripts, decisions, and attachments at rest using a per-organization data key, with TLS protecting traffic in transit.
03
Audit logs and evidence
Security controls are only useful if the board can later understand what happened. Audit logs should show important access, document, approval, and governance events in a way administrators can review.
The best logs connect activity to the meeting, agenda item, document version, user, and role.
- Document uploaded, replaced, viewed, downloaded, or removed
- Access granted, changed, or revoked
- Board pack circulated or revised
- Minutes approved or signed
- Security-sensitive settings changed
04
AI and transcription controls
AI and transcription can improve board workflows, but they also expand the security review. Boards should know which providers process data, whether AI is optional, and how transcripts are stored.
A secure board portal should make these controls explicit instead of hiding them behind a general AI feature label.
- AI can be disabled or limited by policy
- The organization can choose or bring its provider
- Transcription is opt-in per meeting
- Drafts stay separate from approved records
- Provider and subprocessor details are visible
Where BoardKite helps
BoardKite lets organizations choose the AI provider they allow, including hosted defaults, customer-owned provider keys, or self-hosted models. Transcription is opt-in per meeting.
05
Vendor review questions
Use the same questions with every vendor so the comparison is concrete. Ask for a demonstration using realistic board materials: a financial report, a legal memo, a committee update, and a revised board pack.
If a vendor cannot show how access, audit logs, AI controls, and retention work in that scenario, the security posture is probably not mature enough for sensitive governance work.
- Where is data stored and processed?
- Which subprocessors can access board data?
- Can access be revoked after documents are shared?
- Can audit evidence be exported for a meeting?
- How are AI prompts, transcripts, and outputs handled?
- Which controls are available before enterprise pricing?
06
Worked example: nonprofit finance committee
A nonprofit board is reviewing a donor-sensitive budget issue. The finance committee should see the full attachment, the wider board should see the approved summary, and an external observer should see neither. The risk is not only a hacker; it is accidental oversharing by a well-meaning volunteer.
In the security review, ask the vendor to create that exact meeting: one trustee, one finance committee member, one observer, one sensitive paper, and one revised board pack. Then ask them to show the final access state and export the audit trail.
| Threat | Control to verify | Evidence |
|---|---|---|
| Leaked board pack | No public links, scoped access, optional download restrictions | Document access settings and audit events |
| Former director access | Offboarding workflow and role revocation | User removal log and retained historical record |
| AI retention concern | Provider choice, opt-in AI, retention policy, subprocessor visibility | AI configuration screen and data-processing terms |
| Wrong audience for a committee paper | Committee or agenda-item-level access | Demo with observer denied access |
07
Demo script for vendors
Do not evaluate security only from a PDF. Ask vendors to show the controls using a realistic board cycle, then compare what they can prove on screen.
A good demo script is short: upload a confidential finance paper, circulate the pack, revoke access for one observer after circulation, replace the file with a new version, approve minutes, and export the audit for that meeting.
- Show me revoke after circulation
- Show me who viewed the revised board pack
- Show me export audit for one meeting
- Show me where AI is enabled, disabled, and logged
- Show me how a former director is removed while records remain intact
