Introducing Productboard Pulse. Exec-level insights into what your customers need, powered by AI.

Learn more!!
SECURITY & POLICY

6000+ companies trust Productboard

We’ve built our product according to the highest security standards and offer industry-leading administration and access management tools.

https://cdn.builder.io/api/v1/image/assets%2F1d8ecee591ac4358befb8fe998100548%2F625161fd16ca42c5baa530a9c8409d7a

Product security & reliability

Productboard offers many security features, including SAML SSO, IP Whitelisting, audit and changelogs, private views, RBAC, and manage access across multiple workspaces to ensure best-in-class protection.

SSO

Productboard offers SAML Single Sign-on (SSO) to allow admins to determine who has access to Productboard from your existing identity provider/SSO solution — Azure Active DirectoryOneLoginOkta, G Suite, and more. Productboard also supports Google SSO based on OAuth2.0.

Role-Based Access Controls

Access to data within the Productboard application is governed by role-based access controls (RBAC). Productboard has various permission levels for users (maker with admin access, maker, contributor, viewer).

Password and Credential Storage

Productboard enforces a password complexity standard, and stores credentials using a PBKDF function (bcrypt).

Uptime

Productboard has 99% or higher uptime.

IP Whitelisting

Productboard can be configured to only allow access from designated IP address ranges. These restrictions can be applied to all users.

Cloud Security

Productboard’s security and availability architecture is built on top of ISO 27002:2013 controls and SOC 2 Focus Points to enable best practice protection controls, implemented based on industry standards.

Physical Security & Data Hosting

Productboard uses AWS data centers in the United States. The services and data are hosted in Amazon Web Services (AWS) facilities (us-east-1) in the USA.

Dedicated Security Team

Productboard’s Security Team is on call 24/7 to respond to security alerts and events.

Intrusion Detection and Prevention

Productboard has designed multiple layers of security monitoring to detect anomalous behavior. When incidents and security events exceed predetermined thresholds, our 24/7 on-duty security team acts upon it.

DDoS Mitigation

Productboard has designed a multi-layer approach to DDoS mitigation. A core technology partnership with Cloudflare provides network edge defenses, while the use of AWS scaling and protection tools provide deeper protection along with our use of third party DDoS/WAF/RASP application tools.

Logical Access

Access to the Productboard Production Network is restricted by an explicit need-to-know basis, utilizes least privilege, is frequently audited and monitored, and is controlled by our Operations Team. Employees accessing the Productboard Production Network are required to use multiple factors of authentication and complete extensive background checks along with many technical and administrative controls.

Failover and DR

Productboard was built with disaster recovery in mind. All of our infrastructure and data are spread across 3 AWS availability zones and will continue to work should any one of those data centers fail. 

Virtual Private Cloud

All Productboard servers are within our own virtual private cloud (VPC) with network access control lists (ACLs) that prevent unauthorized requests getting to our internal network.

Back Ups and Monitoring

On an application level, Productboard produces audit logs for all activity, ships logs to Datadog for analysis, and uses S3 for archival purposes. All actions taken on production consoles or in the Productboard application are logged.

Permissions and Authentication

Access to customer data is limited to authorized privileged employees who require it for their job responsibilities. Productboard runs a zero-trust corporate network. We have SAML Single Sign-on (SSO), 2-factor authentication (2FA), and strong password policies on OKTA, GitHub, Google, AWS, and Productboard to ensure access to cloud services is protected.

Encryption

All data sent to or from Productboard is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only and score an “A+” rating on Qualys SSL Labs‘ tests. This proves we only use strong cipher suites and have features such as HSTS and Perfect Forward Secrecy fully enabled. We also encrypt data at rest using an industry-standard AES-256 encryption algorithm.

Pentests & Vulnerability Scanning

Productboard uses third party security tools to continuously scan for vulnerabilities. Our dedicated security team responds to issues raised. Annually we engage independent third-party security experts to perform detailed penetration tests on the Productboard application and network.

Security Incident Response

In case of a system alert, events are escalated to Productboard’s 24/7 teams providing Operations, Network Engineering, and Security coverage. Employees are trained on security incident response processes, including communication channels and escalation paths.

Application Security

Productboard practices extensive processes and controls to ensure application security. All Productboard engineers utilize common best practices defined by standards like OWASP, NIST and CIS Benchmark.

Secure Code Development (SDLC)

At least annually, engineers participate in secure code training covering OWASP Top 10 security risks, common attack vectors, and Productboard security controls.

Framework Security Controls

Productboard leverages modern and secure open-source frameworks with security controls to limit exposure to OWASP Top 10 security risks. These inherent controls reduce our exposure to SQL Injection (SQLi), Cross Site Scripting (XSS), and Cross Site Request Forgery (CSRF), among others.

Quality Assurance

Our Quality Assurance (QA) department reviews and tests our code base. Dedicated application security engineers on staff identify, test, and triage security vulnerabilities in code.

Separate Environments

Testing and staging environments are logically separated from the Production environment. No Service Data is used in our development or test environments.

Bug Bounty program

For more information regarding Bug bounty program, please visit this page.

HR Security

At Productboard we ensure that our employees adhere to the highest security standards by implementing extensive employee background checks and multiple administrative controls.

Training

All employees complete Security and Awareness training annually and during onboarding.

Policies

Productboard has developed a comprehensive set of security policies based on ISO 27002:2013 ISMS framework and SOC 2 Trust Criteria Focus Points. These policies are updated frequently and communicated to all employees.

Employee Screening

Productboard performs background checks on all new employees in accordance with local, federal and state laws applicable to our business. The background check includes employment verification, criminal checks, credit checks, deeper historical references and education verification.

Confidentiality

All employee contracts include a confidentiality agreement.

Compliance

Productboard has built its Information Security Management System on top of ISO 27002:2013 controls and SOC 2 Focus Points to ensure the best practice protection controls are implemented based on industry standards and we are compliant with applicable local, federal and state regulations, as well as industry standards.

SOC 2

Productboard is SOC2 Type II certified. If you are interested about the report, please reach out to your account manager or request a copy of the Productboard SOC 2 Type 2 Report.

PCI-DSS

All payments made to Productboard go through Stripe. (Stripe’s security setup and PCI compliance) Productboard has completed PCI-DSS Self-Assessment Questionnaire (SAQ-A) to ensure Compliance with this industry standard.

Privacy & Data Protection


Legal Resources

For information on Productboard’s legal and privacy terms, please visit:


Security concern?

If you think you may have found a security vulnerability, please get in touch with our security team at security@productboard.com

Report a problem

Learn more about security at Productboard