Minimise
Do not collect accounts, payment data, uploads, or live AI prompts before the product has a justified need and a protected handling path.
Boardesa AI is a static product preview with a local workspace. This page separates controls that exist today from safeguards required before live AI, accounts, uploads, or billing can launch.
These labels describe the deployed static preview. They are not a penetration-test certificate or a guarantee that every vulnerability has been found.
The current product intentionally keeps the attack surface smaller while its future backend, data, identity, and payment boundaries are designed.
Do not collect accounts, payment data, uploads, or live AI prompts before the product has a justified need and a protected handling path.
Keep future provider credentials and payment secrets on protected server infrastructure, never inside public HTML or JavaScript.
Bind requests and responses, validate portable sessions, verify content-hashed assets, and reject unexpected transport or cache content.
State inactive services, known limits, reporting routes, and launch gates without inventing certifications, uptime, or security guarantees.
These controls are present in the deploy package and can be inspected without trusting marketing claims.
Scripts and styles are limited to known origins, inline event handlers are blocked, framing is denied, and active content is not loaded from arbitrary CDNs.
Production CSS and JavaScript use content-derived filenames and Subresource Integrity values checked against the deployed files.
The service worker accepts only allowlisted routes and current-build assets with expected origin, status, and MIME type.
Local recovery files include a SHA-256 digest and strict size, schema, age, allowlist, and content-length validation before import. Current files add an integrity-covered export ID so exact replay can be labelled and a previously seen ID with a different fingerprint can be blocked in the current tab. This does not authenticate the author.
Google Analytics remains denied until the user explicitly allows it. No advertising storage or AdSense integration is active.
URL parameters and imported files cannot activate a model provider, remote endpoint, account, upload, or payment flow.
Use ordinary email for a concise, redacted report. Stop testing if an action could expose another person’s information, disrupt availability, alter data, or create avoidable cost.
Security messages are reviewed through email. Boardesa does not promise a bounty, guaranteed response time, or encrypted reporting channel in the current preview.
Confirm whether the report concerns the current public build and contains enough redacted detail to reproduce safely.
Validate the behaviour in an isolated environment without using another person’s data or widening the impact.
Remove or disable an affected path when needed, then correct the underlying code, configuration, or documentation.
Update the reporter when practical and revise public security or status information when a material boundary changes.
Connecting live AI, uploads, accounts, or billing requires controls that a static preview does not yet need.
No certification. This is not a security certification or penetration-test report.
No bounty promise. No reward, response-time, or remediation-time commitment is offered.
No encrypted mailbox. Reports must be minimised and redacted.
No live-service coverage. There is no public AI backend, account platform, upload processor, or payment system.
No. The current workspace is a deterministic local preview.
No public bug bounty is offered. Responsible reports are welcome by email.
Include the affected URL, build, impact, reproducible steps, expected and observed behaviour, and a redacted example.
No. The transport is fixed to local preview.
Not currently. Do not include secrets or unnecessary personal data.
Start with the published policy and a redacted reproduction. Use Help Center for ordinary recovery issues.