Security and vendor diligence
Last updated: 31 July 2026
Your professional obligations make you responsible for client data wherever it sits, including with us. This page answers the questions that responsibility raises, including the ones where the answer is currently “we don’t have that yet”. If your firm needs something here in a signed agreement rather than on a web page, write to yehuda.levy08@gmail.com and we will put it in the contract.
Who you are contracting with
Freeboard is provided by Yehuda Levy, a sole trader registered in Israel, not a company. One person builds and operates it. Subscriptions are sold through Paddle.com, which acts as reseller and merchant of record, so your payment relationship is with Paddle rather than with us directly.
The Terms are governed by the law of Ontario, Canada, and its courts are the forum for any dispute. That is deliberate: a contract you cannot practically enforce is not much of a contract, and asking a Canadian firm to litigate abroad against an individual is not a real remedy.
We are not going to dress the rest of it up. The counterparty is still one person rather than a company. A firm that requires an incorporated counterparty should read what is missing below before going further.
Where your data is
Every firm gets its own database, in its own project, on its own hosting project. Firms are not rows in a shared table separated by a customer column. One firm’s files are never stored alongside another’s, and there is no query we could write by accident that spans two firms.
The region is chosen per firm and fixed at onboarding. If your firm needs its data to stay in Canada, say so before onboarding and the project is created in a Canadian region. If we cannot meet a residency requirement we will tell you instead of working around it.
Who can reach it
- Inside your firm:access is decided by the database on every read, not by hiding menu items. A user reaches only what their role allows, and a confidential matter is invisible to everyone outside its team, including the fact that it exists. These rules have their own automated test suite, which asserts that staff cannot read each other’s tasks, cannot promote themselves, and cannot see other people’s notifications.
- Us: operating your deployment requires administrative access to your database. One person holds it. There is no larger team, and equally no offshore support desk and no subcontractors. We do not read firm content except when you ask us to investigate something specific.
- Our providers: the companies listed below hold the data in the ordinary course of hosting it.
Providers who hold or process data
- Supabase— database and sign-in, in your firm’s chosen region. This is where matters, tasks, and deadlines live.
- Vercel — runs the application itself.
- Paddle — payment processing as merchant of record. Card details go to Paddle and are never held by us.
- Email delivery — deadline reminders and account mail. Reminder emails carry task and matter names, so if your firm would rather they did not leave your building, email alerts are opt-in per user and can stay off. The in-app reminders work either way.
Sign-in
Two-factor authentication is available to every user and can be made mandatory for the firm. The requirement is enforced by the database rather than by a redirect, so it cannot be stepped around by going straight to a page. Accounts are created and removed by your own firm administrator.
Getting your data out
Your matters and tasks export to CSV from the admin screens at any time, without asking us. You do not need a support ticket, and there is no export fee. On termination the data stays available for export for a reasonable period before deletion, as set out in the Terms.
If something goes wrong
If we become aware of a breach affecting your firm’s data we will tell you within 72 hours, with what we know at that point rather than waiting until the picture is complete, and follow up as it develops. You will need that to meet your own notification obligations.
“Become aware” means the point at which a hosting provider notifies us, or we find it ourselves by any other route. The clock starts then, not when we finish working out what happened.
Backups are those of your firm’s own database project, on the plan that project is on. The retention window and restore process for your firm are confirmed in writing at onboarding rather than promised generically here.
What Freeboard does not have
Each of these is a real gap. The condition that closes it is stated next to it, so you can hold us to it or decide it is not enough yet.
- No third-party security audit (SOC 2 or equivalent). No outside auditor has reviewed this. The automated tests covering the access rules are ours, not an auditor’s. Committed: a formal audit begins at ten live firms, or sooner if your own diligence requires one.
- No professional indemnity or cyber insurance. Today our liability is limited to fees paid, as the Terms set out, and there is no policy behind that limit. Committed: technology errors and omissions cover, together with cyber cover, in place before the first paying firm. That commitment is conditional on one thing we do not yet control, and we would rather name it than let you find it later: the policy has to respond to claims brought in Ontario, Canada, and not every insurer will write that from Israel. If we cannot obtain cover that does, we will say so on this page rather than quietly leave the line here.
- One operator, and no source code escrow. If one person becomes unavailable, work on Freeboard stops. There is no second engineer and no escrow arrangement.
What we do instead, because it is worth more than escrow to a firm your size: your database lives in its own project, and on request at any paid tier that project is held in your own provider account, with your firm as the owner. Escrowed source code that nobody is left to run rarely helps anyone. A database you already hold the keys to does. If we disappear, maintenance stops and your access does not. - Not incorporated. The counterparty is an individual, not a company, and is resident in Israel. The forum problem is dealt with by the Terms running under Ontario, Canada law, but that does not make us a company. Committed: incorporation in Canada, subject to advice we are taking now. We will date this here once that advice is in rather than announce a date we might miss.
- No party record behind the conflict check. A matter holds a client and an adverse party, and those are the only parties Freeboard has. Intake screens the two names you enter against those same two fields on every existing file, fuzzily and in both directions. That is a real check, and it is also the whole of it. It cannot see principals, directors, corporate affiliates, related parties, or anyone who was never written on a file, and it runs when the matter is opened rather than again later when the parties on a file change. It searches your own records at the one moment a file is opened. It is not the conflict search itself. Closing it means a party model the check can hold and re-screen as it changes, and that does not exist yet.
- No jurisdiction rules engine. Freeboard counts days around the days your firm tells it the court is closed. It does not know what any deadline is, and it is not a substitute for the rules. This one is a design decision rather than a missing feature: a rules table that quietly went stale would produce a confident, wrong, authoritative-looking date, which is the failure this product exists to avoid.
Questions this page did not answer
Send them to yehuda.levy08@gmail.com. If your firm has a vendor questionnaire, send it as it is and we will complete it, including the parts where the answer is no.