LAST UPDATED · August 21, 2026
How Grit Board protects customer data — what is actually in place today, and what isn't yet. No aspirational claims: if it's written here, it's running.
Grit Board holds sales-team performance data on behalf of its customers. This page describes the security measures actually in place today — and, just as deliberately, the ones that are not in place yet. When something here changes, this page changes with it.
Grit Board does not hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Our infrastructure providers hold their own attestations (Vercel and Nango publish SOC 2 attestations; Vercel is ISO 27001 certified); those are their certificates, not ours, and we do not claim them.
Grit Board runs on Vercel (hosting and edge infrastructure) and Supabase (database and authentication). Stripe processes payments, and Nango operates CRM OAuth connections. The full list of vendors, with what each one touches, is on the Subprocessors page.
Every customer’s data is scoped to their own organization. Grit Board enforces this in two independent layers: every application query is filtered by organization, and the database itself has row-level security enabled on every table as a deny-by-default backstop, so a query that escaped the application layer would still return nothing. An automated script verifies both layers against the live database and is re-run whenever isolation-related code changes.
Within an organization, account owners manage data, settings, and billing; invited reps have read-only access to their boards. These limits are enforced on the server, not just hidden in the interface.
Sign-in is by emailed magic link — no password is ever created for your Grit Board account, so there is no Grit Board password to steal or reuse.
Grit Board is operated by a single founder, who is the only person with administrative access to production systems. Accounts on our infrastructure providers are protected with two-factor authentication.
Customers are responsible for managing their own authorized users, choosing appropriate access levels, and promptly removing users who should no longer have access.
Traffic to Grit Board is served over HTTPS; requests over plain HTTP are redirected, and HTTP Strict Transport Security is enabled on both the marketing site and the app. Data at rest is encrypted by our infrastructure providers — Supabase states that customer data is encrypted at rest with AES-256, and Vercel states the same for data on its platform. Grit Board does not implement its own encryption scheme on top of these.
Grit Board sets standard security headers on both the marketing site and the app, including HSTS, clickjacking protection, and a policy denying camera, microphone, and location access. Expensive and destructive endpoints are rate-limited. Continuous integration builds, runs the test suite, and fails on any high or critical dependency advisory before code can ship.
Grit Board only reads from your CRM. It never creates, edits, or deletes records in your CRM, and it syncs only the fields your configured mapping requires.
When you connect a CRM, the OAuth tokens are held by Nango, our OAuth infrastructure provider, which encrypts them and injects them into requests on our behalf. Grit Board’s own database never stores your CRM access or refresh tokens. You can disconnect a CRM at any time from the integrations settings, which deletes the stored connection.
Grit Board currently runs manual, on-demand database exports rather than continuous automated backups, and does not offer point-in-time recovery. Automated daily backups are planned before the first paying customer. Customers can export a full copy of their own data at any time from account settings, and most board data can be restored by re-uploading a CSV or re-running a CRM sync.
Grit Board maintains a written incident-response runbook covering suspected token compromise, unauthorized access, and provider incidents, including a tested procedure for immediately revoking every CRM connection. It was last rehearsed in August 2026.
If a security incident affects customer-controlled personal data, Grit Board will notify affected customers as required by applicable law and any signed agreement or DPA.
Named plainly so you don’t have to ask: no SOC 2 or other formal certification, no third-party penetration test, no bug-bounty program, no continuous automated backups (see above), and monitoring is currently manual review of sync and import logs rather than automated alerting. Each of these is on the roadmap in roughly that reverse order; this list shrinks as the product grows.
Customers are responsible for using strong authentication practices, controlling workspace access, keeping source systems secure, uploading or syncing only data they are authorized to process, and reviewing product outputs before using them for employment or compensation decisions.
Security concerns can be reported to hello@gritboard.io. Please include enough detail for us to understand and reproduce the issue where possible.
If you research in good faith and report privately, we will not pursue legal action over that research. A machine-readable contact lives at /.well-known/security.txt.