Trust Centre
Security & data protection
How we protect customer data, who processes it, and what we commit to. Published by Pitchara Ltd, trading as Everboarder.
Last updated: 17 August 2026
Our approach
Everboarder does not hold its own SOC 2 certification at this stage. Our platform is built on subprocessors that are independently certified — Supabase (SOC 2 Type II, on AWS), Google Cloud (ISO 27001, SOC 2), ElevenLabs (SOC 2 Type II, ISO 27001, PCI DSS Level 1), Resend (SOC 2 Type II), Firecrawl (SOC 2 Type II) and HubSpot (SOC 2 Type II). This is inherited assurance, not our own attestation, and we prefer to be upfront about that distinction.
What we take accountability for is how that certified infrastructure is configured and used: strict tenant isolation, data minimisation, clear retention rules, and transparent subprocessor disclosure. Below is our Baseline standard, applied to every customer by default, and our Enterprise tier, available on request for organisations with additional regulatory, procurement, or data residency requirements.
Baseline protection (all customers)
Data architecture
- Multi-tenant isolation via PostgreSQL row-level security — every table scoped to the owning organisation, so no tenant can query another tenant's data at the database layer, not just the application layer.
- Encryption in transit (TLS 1.2+) and at rest (AES-256), inherited from Supabase/AWS infrastructure.
- Business logic and AI scoring run server-side in edge functions, never exposed to the browser.
Legal & governance
- Data Processing Agreement (DPA) available on request, aligned to UK GDPR and EU GDPR.
- Published subprocessor list (below), reviewed quarterly.
- Defined data retention periods, with deletion on request — right to erasure honoured within 30 days.
- Data minimisation applied: only data required for the stated purpose is collected.
Access control
- Role-based access (Learner / Manager / Admin / Super Admin) with least-privilege defaults.
- Multi-factor authentication enforced on all internal admin accounts (Supabase, GitHub, Google Workspace).
- No shared credentials; team secrets held in a dedicated password manager.
AI governance
- Where AI supports decisions with regulatory weight (for example candidate screening), a human review step remains the authoritative decision-maker — consistent with the EU AI Act's treatment of recruitment AI as high-risk.
- AI processing is documented per feature: what data enters, which model processes it, and what is retained.
Incident response
- Named internal contact for security and privacy incidents.
- Commitment to notify affected customers and, where required, the ICO, within 72 hours of becoming aware of a qualifying breach.
Backup & continuity
- Automated daily backups via Supabase infrastructure.
- Point-in-time recovery available.
Enterprise tier (on request)
Available for organisations with additional compliance, procurement, or architectural requirements. Each of the following is scoped individually — they are not included in the baseline standard above:
- SOC 2 Type II — Everboarder's own organisational certification, distinct from the inherited subprocessor certifications listed below.
- ISO 27001 certification.
- Data residency — dedicated regional deployment (EU-only or US-only storage).
- Single-tenant / dedicated infrastructure options.
- Bring your own LLM — connect your own model provider in place of our default scoring pipeline, subject to a compatibility and validation exercise against our rubric-driven scoring standards.
- Custom DPA / MSA terms, indemnity and liability negotiation.
- Third-party penetration testing — annual report shared under NDA.
- SSO / SAML integration.
- Audit log export for customer-side compliance monitoring.
- Dedicated voice AI agent provisioning rather than shared-tier voice infrastructure.
- Uptime SLA with service credits.
To discuss enterprise requirements, email hello@everboarder.com or request a demo.
Current subprocessors
Certification statuses were verified via each vendor's public trust centre in July 2026 and are re-verified at each quarterly review.
| Subprocessor | Purpose |
|---|---|
| Supabase (AWS)SOC 2 Type II | Database, authentication, edge functions, storage |
| Google Cloud (Gemini)ISO 27001, SOC 2 | AI scoring and content generation |
| ElevenLabsSOC 2 Type II, ISO 27001, PCI DSS Level 1, HIPAA & GDPR attestations | Conversational voice AI for roleplay |
| ResendSOC 2 Type II, GDPR compliant | Transactional email |
| PostHog (EU)EU-hosted | Product analytics |
| HubSpotSOC 2 Type II | CRM / GTM sync (read-only ingest) |
| FirecrawlSOC 2 Type II, GDPR compliant, DPA available | Web enrichment |
Review cycle
This page is reviewed quarterly, or whenever there is a material change to our infrastructure, subprocessors, or regulatory obligations.
Related policies
- Privacy Policy — what personal information we collect and your rights over it.
- Terms of Service — the terms governing use of our services.
Contact
Security, privacy, or vulnerability disclosure questions: email hello@everboarder.com. Please include enough detail for us to reproduce any issue you are reporting.
