Security & data protection
Your risk register is your most sensitive document. We treat it as such.
Hosting
Application data (register, incidents, reports) is stored in a managed PostgreSQL database at Supabase, hosted in Switzerland (AWS eu-central-2, Zurich). The application is served by Vercel, outside Switzerland. Hosting entirely in Switzerland, application layer included, remains under review for clients who require it.
Encryption
All communications are encrypted in transit (TLS 1.2+). Data is encrypted at rest (AES-256). Passwords are never stored in clear text (bcrypt hashing).
Isolation by organisation
Each organisation can access only its own data. This isolation is enforced at database level (PostgreSQL Row Level Security), not only in the application: even in the event of an application defect, the database refuses to serve another organisation's data.
This design has been submitted to four successive adversarial security reviews (multi-tenant isolation, write paths, OHS module, back office), each followed by hardening fixes — in particular: functions with a fixed search_path, uniqueness and length constraints in the database, cross-table consistency checks, systematic server-side validation of inputs.
Backups
Automatic daily backups of the database (Supabase), with retention allowing restoration in the event of an incident.
Access policy
No member of the team accesses your data without your explicit request (support). The platform administration console is restricted to the founder, protected by authentication, and access to the infrastructure is logged by our processors (Supabase, Vercel).
Data protection (FADP)
RiskBoard undertakes to process data in accordance with the Federal Act on Data Protection (FADP). For pilots and contracts, a data processing agreement (DPA) is provided on request. Your data belongs to you: export and complete deletion on simple request, free of charge and without artificial delay.
AI analysis in horizon scanning
The Horizon scanning page proposes a selection of emerging risks tailored to your organisation. To establish it, we transmit to Anthropic PBC (United States) the name of your organisation, its sector, and the list of the risks in your register (code, title, category). Neither the details of the risks, nor the action plans, nor the OHS incidents, nor any personal data are transmitted.
This transfer takes place only when you launch the analysis — never in the background. Anthropic does not train its models on the data received through its API. The legal basis for the transfer is the standard contractual clauses (art. 16 para. 2 let. d FADP).
What we do not do
No resale or sharing of data. No AI model training on your data. Not one sentence of your reports is written by an AI: all figures are calculated, traceable and reproducible. The only exception is horizon scanning, whose comments are generated and flagged as such in the interface (see above).
Publisher & contact
RiskBoard is published by Jaures Adjamonsi (sole proprietorship), canton of Vaud, Switzerland.
A question about security, a need for a DPA, or a particular hosting requirement? Write to contact@riskboard.ch — the founder replies in person.