Sessionboard maintains an information security and compliance program covering technical controls, vendor oversight, and required employee knowledge and training. Related documents: Privacy Policy · Sub-processors · AI FAQs · DPA.
SOC 2 Type II
Sessionboard has achieved SOC 2 Type II certification. An independent auditor reviewed our controls against the SOC 2 Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). The report is available to customers and prospects on request.
General Data Protection Regulation (GDPR)
European Economic Area-origin personal data is processed and stored on the basis of the Standard Contractual Clauses, as amended by the European Commission, with appropriate technical, contractual, and organizational supplementary measures. See our Privacy Policy, GDPR & CCPA page, and Data Processing Addendum.
California Consumer Privacy Act (CCPA), as amended by the CPRA
Sessionboard maintains internal procedures and processes to comply with the CCPA as amended by the California Privacy Rights Act. See our Privacy Policy for more information.
Third-party sub-processors
Sessionboard uses third-party sub-processors to provide features of the platform. All third parties are subject to a security, compliance, and privacy assessment before contracting. Approved vendors are reassessed at least annually. The current list is at List of Sub-processors.
Cookies
When you visit Sessionboard’s website, we and our service providers collect certain data using tracking technologies such as cookies and web beacons. See our Cookie Policy.
Sessionboard AI features send only the fields needed to generate output (for example session titles, descriptions, and speaker bios) to enterprise APIs of our AI sub-processors. We use a closed-processing model: customer data is not used to train provider models and is not retained by the provider beyond generating the response. Communications with those APIs are encrypted in transit (TLS 1.2 or higher). See Sessionboard AI FAQs and the sub-processor list. Customers can ask that AI-powered features be disabled.
Data centers
The Sessionboard product runs on Amazon Web Services (AWS) in the continental United States and Ireland (EU). Sessionboard does not own the hardware in those data centers. AWS is responsible for security of the underlying cloud infrastructure (IaaS / PaaS). Sessionboard is responsible for controls and configurations from the operating system layer up.
Google Cloud is used for specific AI services (including speech-to-text, translation, NLP, and Gemini), not as a primary host of the Sessionboard application. Those uses are listed on the sub-processor list.
Platform
Sessionboard is a multi-tenant, cloud-based application engineered for scalability, reliability, security, and performance. Platform components are tested regularly.
Encryption
Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access to databases is encrypted. Each customer’s data is hosted in a multi-tenant environment and logically segregated using a unique key.
Network security
Sessionboard divides its platform into separate network groups. Network controls are designed to prevent unauthorized access to and within the product infrastructure. Internal restrictions limit which device types can communicate. Intrusion detection / prevention is deployed, with near real-time alerts for suspicious activity.
Secure development & change management
Sessionboard has a formal development and change management process: identification and recording of significant changes, risk assessment, approval, and testing before production. Changes to infrastructure and software are developed and tested in a separate environment. Access to source-code management is limited to a business need and reviewed quarterly. Static code analysis is part of the development process.
Personnel
Where applicable, new Sessionboard personnel (employees, contractors, interns) sign an NDA and pass a background check. Information security and compliance onboarding is required at hire, with web-based training at hire and annually. Phishing simulations run quarterly. Personnel review and acknowledge applicable policies at least annually and at hire.
Access Management
Sessionboard uses role-based least-privilege access. Privileged access requires a ticketed business justification and manager approval, and is reviewed quarterly. On role change or termination, physical and logical access is removed within 24 hours.
Incident Management
Sessionboard has policies and procedures for security and privacy events. We determine exposure and source, then communicate promptly to affected customers via in-product messaging, email, and our status page, with periodic updates as needed. Report concerns to support@sessionboard.com.
Monitoring, Logging & Alerting
Automated monitoring, alerting, and response cover error rates, unexpected activity, and similar signals. Application logs include logins (success and failure), page visits, actions, and modifications. Logs are protected from change.
Endpoint Protection
Workstations use commercial enterprise antivirus/malware protection with centralized logging. Assets use full-disk encryption (FileVault), passwords, and auto-lock when idle. Agent-based management supports application control, configuration, web filtering, removable-storage restrictions, and remote wipe/lock.
Risk Assessment
Sessionboard regularly reviews risks to its service commitments, including security-event logs, vulnerability assessments, and a formal annual information security risk assessment. Independent third parties conduct annual application-level (web and APIs) and infrastructure-level penetration tests (black, grey, and white-box). Findings are remediated according to policy.
Last Modified: September 8, 2026