Security and vendor diligence
Last updated: 10 August 2026
Your professional obligations make you responsible for client data wherever it sits, including with us. This page answers the questions that responsibility raises, including the ones where the answer is currently “we don’t have that yet”. If your firm needs something here in a signed agreement rather than on a web page, write to hello@getfreeboard.com and we will put it in the contract.
Who you are contracting with
Freeboard is provided by Yehuda Levy, a sole trader registered in Israel, not a company. One person builds and operates it. Subscriptions are sold through Paddle.com, which acts as reseller and merchant of record, so your payment relationship is with Paddle rather than with us directly.
The Terms are governed by the law of Ontario, Canada, and its courts are the forum for any dispute. That is deliberate: a contract you cannot practically enforce is not much of a contract, and asking a Canadian firm to litigate abroad against an individual is not a real remedy.
We are not going to dress the rest of it up. The counterparty is still one person rather than a company. A firm that requires an incorporated counterparty should read what is missing below before going further.
Where your data is
Every firm gets its own database, in its own project, on its own hosting project. Firms are not rows in a shared table separated by a customer column. One firm’s files are never stored alongside another’s, and there is no query we could write by accident that spans two firms.
The region is chosen per firm and fixed at onboarding. If your firm needs its data to stay in Canada, say so before onboarding and the project is created in a Canadian region. If we cannot meet a residency requirement we will tell you instead of working around it.
Who can reach it
- Inside your firm:access is decided by the database on every read, not by hiding menu items. A user reaches only what their role allows, and a confidential matter is invisible to everyone outside its team, including the fact that it exists. These rules have their own automated test suite, which asserts that staff cannot read each other’s tasks, cannot promote themselves, and cannot see other people’s notifications.
- Us: operating your deployment requires administrative access to your database. One person holds it. There is no larger team, and equally no offshore support desk and no subcontractors. We do not read firm content except when you ask us to investigate something specific.
- Our providers: the companies listed below hold the data in the ordinary course of hosting it.
Providers who hold or process data
- Supabase holds the database and sign-in, in your firm’s chosen region. Matters, tasks and deadlines live there.
- Vercel runs the application itself.
- Paddle processes payment as merchant of record. Card details go to Paddle and are never held by us.
- An email provider delivers deadline reminders and account mail. Those reminders carry task and matter names, so if your firm would rather they did not leave your building, email alerts are opt-in per user and can stay off. The in-app reminders work either way.
Sign-in
Two-factor authentication is available to every user and can be made mandatory for the firm. The requirement is enforced by the database rather than by a redirect, so it cannot be stepped around by going straight to a page. Accounts are created and removed by your own firm administrator.
Getting your data out
Any single file exports from its own page, and every file at once from the admin screens: a zip of CSVs holding the file’s details, its parties, the memo to file, events, team, tasks, notes, recorded changes, document links and time. You do it yourself, at any time, without asking us. There is no support ticket and no export fee. A table with nothing in it still gets its CSV, carrying the header alone, because “there was none” and “we did not give you this” are different answers. On termination the data stays available for export for a reasonable period before deletion, as set out in the Terms.
If we stop
Every firm’s data sits in its own database project, not in a shared table with a customer column. That is a security decision first, and a continuity decision second, and the second is the one worth reading here: the database is not ours to hold.
At any paid tier, on request, your firm’s database project is held in your own provider account, with your firm as the account owner and us as a collaborator you can remove. Ask for it at onboarding and it is set up that way from the start; ask for it later and it is a migration we run, at no charge, once per firm. You hold the credentials either way.
So the answer to what happens if this operator is hit by a bus is not a promise about a successor: development stops, support stops, and your data does not move, disappear, or become hostage. It is in an account you own, on a mainstream Postgres host, in a schema you can read, and the export described above keeps working because it runs in your firm’s own deployment. The worst case is a system that stops improving while you take an unhurried decision about what to move to.
What this is not: source code escrow. Escrow hands a firm a codebase nobody is left to run, which for a firm of ten is a filing cabinet full of TypeScript. If your insurer or your diligence process specifically requires escrow, say so and we will arrange it, but we would rather you had the database.
If something goes wrong
If we become aware of a breach affecting your firm’s data we will tell you within 72 hours, with what we know at that point rather than waiting until the picture is complete, and follow up as it develops. You will need that to meet your own notification obligations.
“Become aware” means the point at which a hosting provider notifies us, or we find it ourselves by any other route. The clock starts then, not when we finish working out what happened.
Backups are those of your firm’s own database project, on the plan that project is on. The retention window and restore process for your firm are confirmed in writing at onboarding rather than promised generically here.
What Freeboard does not have
Each of these is a real gap. The condition that closes it is stated next to it, so you can hold us to it or decide it is not enough yet.
- No third-party security audit (SOC 2 or equivalent). No outside auditor has reviewed this. The automated tests covering the access rules are ours, not an auditor’s. Committed: a formal audit begins at ten live firms, or sooner if your own diligence requires one.
- No professional indemnity or cyber insurance. Today our liability is limited to fees paid, as the Terms set out, and there is no policy behind that limit. Committed: technology errors and omissions cover, together with cyber cover, in place before the first paying firm. That commitment is conditional on one thing we do not yet control, and we would rather name it than let you find it later: the policy has to respond to claims brought in Ontario, Canada, and not every insurer will write that from Israel. If we cannot obtain cover that does, we will say so on this page rather than quietly leave the line here.
- One operator, and no source code escrow. If one person becomes unavailable, work on Freeboard stops. There is no second engineer, no on-call rota, and no escrow arrangement. What that does and does not reach is set out under If we stop above: development and support end, your access to your own database does not.
- Not incorporated. The counterparty is an individual, not a company, and is resident in Israel. The forum problem is dealt with by the Terms running under Ontario, Canada law, but that does not make us a company. Committed: incorporation in Canada, subject to advice we are taking now. We will date this here once that advice is in rather than announce a date we might miss.
- The conflict check knows names, not relationships. A matter holds its client and as many adverse parties as it has, each with the counsel acting for them. Intake screens every one of those names against the client, the file name and the parties on every existing file, fuzzily and in both directions, and adding a party to a file later screens that party too and appends the result rather than overwriting what intake found. What it has no model of is how parties relate to each other. It cannot see principals, directors, corporate affiliates, parent companies, or anyone who was never written on one of your files. A numbered company and the person behind it are two unrelated strings to it. So it searches the names your firm has recorded, which is a real check and worth having, and it is not the conflict search your professional obligations describe. Closing this means holding entities and the relationships between them, and that does not exist yet.
- No jurisdiction rules engine. Freeboard counts days around the days your firm tells it the court is closed. It does not know what any deadline is, and it is not a substitute for the rules. This one is a design decision rather than a missing feature: a rules table that quietly went stale would produce a confident, wrong, authoritative-looking date, which is the failure this product exists to avoid.
Questions this page did not answer
Send them to hello@getfreeboard.com. If your firm has a vendor questionnaire, send it as it is and we will complete it, including the parts where the answer is no.