BoardReady

Documents

How we handle your documents

Board packages include tax returns, bank statements, and employment letters. Those stay with the agent who uploaded them. This is what we actually do — not a certification badge.

  1. 1

    Encrypted so storage cannot read them

    Client documents sit in a private object store, encrypted with a key we hold. The storage vendor cannot decrypt the files. The browser never receives the storage path — preview and download go through a short-lived link for one object.

  2. 2

    Only the account that created a package can open it

    A package belongs to the signed-in agent who created it. Another account asking for that id gets nothing back — not a hint that it exists. Guessing an id does not produce someone else's tax return.

  3. 3

    Models do not keep a copy

    We have to read the files to classify and assemble them. We do not send them to labs that retain prompts or train on them. Production uses AWS Bedrock and Cerebras Cloud for that reason. Hosts that keep or train on customer data (including OpenAI and DeepSeek) are refused. Anthropic is a fallback and may keep safety logs for up to 30 days unless zero-data-retention is on.

  4. 4

    The card never touches us

    The assembled PDF unlocks through Stripe's hosted Checkout. We never see the card number. A download link is bound to one file and expires in two minutes — a leaked link is not a login.

What this page does not claim

We are not SOC 2 or HIPAA certified. We process documents in order to assemble the package — we do not claim we never see them. Losing the encryption key makes stored files unreadable, which is the point of holding the key ourselves.

More on board package document privacy, or the NYC board package guides.

← NYC co-op & condo board package software