everboarder

Trust Centre

Security & data protection

How we protect customer data, who processes it, and what we commit to. Published by Pitchara Ltd, trading as Everboarder.

Last updated: 17 August 2026

Our approach

Everboarder does not hold its own SOC 2 certification at this stage. Our platform is built on subprocessors that are independently certified — Supabase (SOC 2 Type II, on AWS), Google Cloud (ISO 27001, SOC 2), ElevenLabs (SOC 2 Type II, ISO 27001, PCI DSS Level 1), Resend (SOC 2 Type II), Firecrawl (SOC 2 Type II) and HubSpot (SOC 2 Type II). This is inherited assurance, not our own attestation, and we prefer to be upfront about that distinction.

What we take accountability for is how that certified infrastructure is configured and used: strict tenant isolation, data minimisation, clear retention rules, and transparent subprocessor disclosure. Below is our Baseline standard, applied to every customer by default, and our Enterprise tier, available on request for organisations with additional regulatory, procurement, or data residency requirements.

Baseline protection (all customers)

Data architecture

  • Multi-tenant isolation via PostgreSQL row-level security — every table scoped to the owning organisation, so no tenant can query another tenant's data at the database layer, not just the application layer.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256), inherited from Supabase/AWS infrastructure.
  • Business logic and AI scoring run server-side in edge functions, never exposed to the browser.

Legal & governance

  • Data Processing Agreement (DPA) available on request, aligned to UK GDPR and EU GDPR.
  • Published subprocessor list (below), reviewed quarterly.
  • Defined data retention periods, with deletion on request — right to erasure honoured within 30 days.
  • Data minimisation applied: only data required for the stated purpose is collected.

Access control

  • Role-based access (Learner / Manager / Admin / Super Admin) with least-privilege defaults.
  • Multi-factor authentication enforced on all internal admin accounts (Supabase, GitHub, Google Workspace).
  • No shared credentials; team secrets held in a dedicated password manager.

AI governance

  • Where AI supports decisions with regulatory weight (for example candidate screening), a human review step remains the authoritative decision-maker — consistent with the EU AI Act's treatment of recruitment AI as high-risk.
  • AI processing is documented per feature: what data enters, which model processes it, and what is retained.

Incident response

  • Named internal contact for security and privacy incidents.
  • Commitment to notify affected customers and, where required, the ICO, within 72 hours of becoming aware of a qualifying breach.

Backup & continuity

  • Automated daily backups via Supabase infrastructure.
  • Point-in-time recovery available.

Enterprise tier (on request)

Available for organisations with additional compliance, procurement, or architectural requirements. Each of the following is scoped individually — they are not included in the baseline standard above:

  • SOC 2 Type II — Everboarder's own organisational certification, distinct from the inherited subprocessor certifications listed below.
  • ISO 27001 certification.
  • Data residency — dedicated regional deployment (EU-only or US-only storage).
  • Single-tenant / dedicated infrastructure options.
  • Bring your own LLM — connect your own model provider in place of our default scoring pipeline, subject to a compatibility and validation exercise against our rubric-driven scoring standards.
  • Custom DPA / MSA terms, indemnity and liability negotiation.
  • Third-party penetration testing — annual report shared under NDA.
  • SSO / SAML integration.
  • Audit log export for customer-side compliance monitoring.
  • Dedicated voice AI agent provisioning rather than shared-tier voice infrastructure.
  • Uptime SLA with service credits.

To discuss enterprise requirements, email hello@everboarder.com or request a demo.

Current subprocessors

Certification statuses were verified via each vendor's public trust centre in July 2026 and are re-verified at each quarterly review.

SubprocessorPurpose
Supabase (AWS)SOC 2 Type IIDatabase, authentication, edge functions, storage
Google Cloud (Gemini)ISO 27001, SOC 2AI scoring and content generation
ElevenLabsSOC 2 Type II, ISO 27001, PCI DSS Level 1, HIPAA & GDPR attestationsConversational voice AI for roleplay
ResendSOC 2 Type II, GDPR compliantTransactional email
PostHog (EU)EU-hostedProduct analytics
HubSpotSOC 2 Type IICRM / GTM sync (read-only ingest)
FirecrawlSOC 2 Type II, GDPR compliant, DPA availableWeb enrichment

Review cycle

This page is reviewed quarterly, or whenever there is a material change to our infrastructure, subprocessors, or regulatory obligations.

Related policies

Contact

Security, privacy, or vulnerability disclosure questions: email hello@everboarder.com. Please include enough detail for us to reproduce any issue you are reporting.