Security & compliance
Examiner-ready.By default.
Access to CUboardroom is restricted externally and internally to preserve confidentiality at every level. Nothing about your board's business travels as an email attachment.
Multifactor authentication
MFA is required for every user, so only authorized users and administrators reach the portal — no shared passwords, no exceptions.
Private cloud hosting
Hosted on Rackspace private cloud in a tier 3 data center that holds SOC 1 Type 2 and SOC 2 Type 2 reports, and ISO 27001 certification.
Granular access controls
Item-level group security with separate internal and external restrictions, overseen by a dedicated security officer.
Encryption & geo-blocking
Data encrypted in transit and at rest, with geo-location blocking that refuses access from malicious regions.
Hardened infrastructure
Web application firewall, intrusion detection and prevention, RAID storage with daily backups, and 24/7/365 monitoring.
A redundant environment
Redundancy through the stack, so a single failure never takes your board's record offline in the week before a meeting.
No email attachments
The packet neverleaves the room.
The risk in most board processes is not the portal — it is everything around it. Packets are forwarded to personal inboxes, printed agendas are left in the car, a spreadsheet of votes is emailed to the chairperson.
CUboardroom removes the reason any of that happens. Directors read, annotate, discuss, and vote inside the portal, and administrators can restrict a single document to a single group. What examiners ask for is already there, already logged.
Request a demo
Bring yoursecurity questions.
We will walk your team through the controls in detail, and put you in front of someone who can answer for them.
Common questions
What your examinerswill ask.
Is multifactor authentication required?
Yes. Every user and administrator must use MFA, and there are no exceptions or shared passwords.
Where is CUboardroom hosted?
CUboardroom runs on Rackspace private cloud in a tier 3 data center. That data center holds SOC 1 Type 2 and SOC 2 Type 2 reports and ISO 27001 certification.
Where is our data stored?
All CUboardroom data stays in the United States.
Is board data encrypted?
Yes. Data is encrypted in transit and at rest. Geo-location blocking also refuses access from malicious regions.
What infrastructure protections are in place?
CUboardroom uses a web application firewall, intrusion detection and prevention, RAID storage with daily backups, and 24/7/365 monitoring. Redundancy runs throughout the stack, so no single failure takes the portal offline.
Can we restrict a document to specific directors or committees?
Yes. Security works at the item level by group, with separate internal and external restrictions, so a single document can be limited to a single group. A dedicated security officer oversees access controls.
How long are vote records kept?
Vote logs stay on your site until your site administrator deletes them, so your credit union controls retention.
What activity can administrators audit?
Administrators can see login activity and which documents each user accessed. The site shows this for a rolling 12 months.
Will CUboardroom help us during an NCUA or state exam?
Yes. It is designed to be examiner-ready. Board business stays inside the portal instead of going out as email attachments or printed copies, so the activity examiners ask about is already recorded and logged.