Skip to main content

Help us improve the Digital Marketplace - send your feedback

BOARD INTELLIGENCE LTD

The Board Intelligence Portal

The Board Intelligence G‑Cloud Platform is a secure board‑management system supporting the full board cycle. Governance teams manage agendas, papers, packs, and actions; executives receive clear briefs; and board members access, annotate, and sign documents across devices, enhanced by AI tools that streamline preparation and insight.

Features

  • ISO 27001-accredited security for your most confidential information
  • Library bookcase and bookshelf layout to manage separate committees
  • Access materials offline securely via native apps
  • Sign documents with E-Signature tool
  • Smart annotations with secure sharing of comments
  • Agenda Planner: Plan meeting agendas that focus on what matters
  • Report Briefer: Commission papers with clear expectations and streamlined workflows
  • Insight Driver: AI-powered tools to surface insights for Readers
  • Minute Writer: turn notes, recordings into high-quality minutes with AI
  • Board Evaluation: Customisable surveys to identify improvement areas

Benefits

  • Plan board and committee agendas aligned with strategic priorities
  • Manage the end-to-end board cycle in one platform
  • Save hours, by building and distributing board packs within minutes
  • Save over 40% of your time spent on drafting minutes
  • Manage late papers easily with simple, instant republishing
  • Increase security, control, auditability and be GDPR Compliant

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at solutions@boardintelligence.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 7 8 2 4 8 2 3 9 1 1 4 0 0 9

Contact

BOARD INTELLIGENCE LTD Joel Nunes
Telephone: 02071928200
Email: solutions@boardintelligence.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Where a planned outage is required, we will notify users two weeks in advance of any outage event. Planned outages are very rare and normally completed midnight UK time
System requirements
  • Web: Any device/laptop etc, running a modern Web Browser
  • Desktop Apps (min OS): MacOS 13.7, Windows 10/11
  • Mobile Apps (min OS): iOS 16.7, iPadOS 16.7
  • Browser support for Chrome, Firefox, Safari, Edge
  • No on-site server installation or desktop installations required
  • Processor, memory and storage requirements are negligible

User support

Email or online ticketing support
Yes
Support response times
We a provide UK-based, 24/7 concierge-standard support service and aim to respond immediately to phone calls and within two hours to emails. On the rare occasions where we are unable to resolve a support request immediately, we will prioritise the support requests according to the following criteria: 1. Critical: Service down or users unable to use the system. 2. Serious: Service operational but with degraded functionality. 3. Inconvenient: Performance issue mildly affecting some but not all users. Routine technical issue. 4. Cosmetic:Information request or change request.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
All clients receive our best, concierge-standard, dedicated 24/7 support. Our 24-hour support team act as a first port of call for any support needs, responding to and resolving most issues at the first point of contact. This includes access to technical staff. Clients also have a dedicated account manager who will work with you to ensure that the service is set up in the best way for you and that you get the most out of everything we do. We will include regular reviews of usage, support and service levels and feature requests. You also have an escalation pathway direct to our senior management team.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Our dedicated onboarding team will ensure that you are set up for success using Board Intelligence.
SET UP
1. Technical: we create your unique instance and run our full suite of quality and security tests.
2. Structure: we will work with you to design and set up your personalised platform structure, which is optimised for your board and committees.
3. Users: we will set up your users and also train your administrators to ensure they have control over managing your user permissions.
TRAINING
1. Training to ensure every user is fully supported to make the most of using the portal.
2. Administrators: everything needed to manage the platform and publish packs.
3. Readers: bespoke sessions which can be individual, in groups or even by attending your board meeting.
4.Resources: guides, videos, refresher sessions and webinars are available for all clients.
ONGOING USE & SUPPORT
1. First meeting: we are happy to attend your meeting to ensure everything goes smoothly, offering hands-on 1-1 support, and providing functionality overviews.
2. Regular reviews: we offer regular reviews of service levels and feature improvements.
3. Ongoing support: we provide a full 24/7/365 support service from our product specialist team.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Video
End-of-contract data extraction
Clients' users with the appropriate permissions, can download a PDF version of every pack at anytime. All data can be downloaded in the format in which it was uploaded, in aggregated PDFs and with annotations.
End-of-contract process
All data remains secure and available to the client to extract in standard formats. We use data eradication techniques to ensure that all client data is securely erased from our systems. This is included in the contract price. Our offboarding process takes 30 days to allow users to extract their data in good time before access is removed and the data is permanently deleted.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our PDFs are readable by screen readers

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • IOS
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our native Apps (Windows 10/11 and macOS/iOS/iPadOS ) are designed for directors, trustees, governors and executives to use to securely receive, annotate, search, and sign their board materials. They feature secure offline storage for board packs, device approval to allow logins only from approved devices, and secure syncing of annotations across devices.
Access through a browser, allows admins and managers to manage the platform, and create board packs for dissemination to readers. You can also permission reader users to be able to download packs through our web interface and request documents to be signed remotely by the directors.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service interface is accessed via a secure browser and allows managers to create and distribute board packs, to manage users and their access rights and to access the audit trail.
Accessibility standards
None or don’t know
Description of accessibility
Our platform has been built with the four core accessibility principles (Perceivable, Operable, Understandable, Robust) in mind. It meets some but not all of the common criteria, for example; Non-text content is limited to buttons and icons which all have a text name describing their functionality, and we do not use colour as the only means of determining status.
Accessibility testing
We have completed an initial assessment of the platform for use with screen readers. Improvements needed to formally meet accessibility standards forms part of our roadmap
API
Yes
What users can and can't do using the API
API endpoints are currently available for retrieving audit log, user permissions snapshot or revoking user entitlements.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customisation of the service is possible. This includes: - Board pack branding and covers -Security configurations (IP constraints, password complexity, MDA, 2FA etc.) - Training and implementation plans to suit your requirements. Customisations are carried out by our team at the request of your nominated points of contact.

Scaling

Independence of resources
We perform regular capacity planning which ensures we are able to meet our client's growing needs, and ensure there is always sufficient buffer for high usage. We consistently monitor platform usage and are able to scale up or down individual clients' resource allocation as required. With our containerised architecture we are also able to isolate high usage platforms to avoid any effect to other users, while we investigate and remediate the cause.

Analytics

Service usage metrics
Yes
Metrics types
Full audit trail of activity in CSV format from which clients can see who did what and when. All actions are categorised and time stamped so can be reported on and analysed in a variety ways. Including: - Logins - Pack edits and publishes -Downloads - Access rights changes - Annotations.
A system screen in the administrator environment is available to review the above information at anytime. We also summarise the key usage stats for our client review meetings.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users with the appropriate permissions are able to export all packs through our management interface and through the app with or without annotations
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Original format in which they were uploaded
Data import formats
  • CSV
  • Other
Other data import formats
  • PDF
  • Microsoft Office formats: Word, PowerPoint, Excel

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Uptime guarantee: 99.9%
Restoration target in event of disaster recovery incident (RTO): 4 hours
Target state in event of disaster recovery incident (RPO): Less than 30 minutes of data loss.
Approach to resilience
We operate over multiple data centres in the UK. Our set-up is active-active-active with each location kept in near real-time sync. Our architecture is set up so that failure of a data centre or piece(s) of hardware in a data centre do not affect the ability of our service to operate.

More details available on request.
Outage reporting
Email alerts and proactive communication from our support team and your account manager.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Readers can login with their username and password to any of our native apps. Device Authorisation functionality can be enabled on request for app users. Managers can login through our web portal also using their username and password. We can enable two-factor (over SMS or authenticator app), and IP range restrictions for web users. We are also able to offer SSO integration with all leading identity providers (using SAML 2.0). Our platform can support a mixed login experience where some users can login without SSO if required.
Access restrictions in management interfaces and support channels
Access is strictly controlled. Clients are able to manage their own platforms directly including users and permissions. Clients can also nominate specific users to have ability to request changes of their platform through our support team. Our support staff have access only to basic user information, management, and troubleshooting tools with no access to client board pack data. Privileged access is restricted to client administrators and limited senior members of our technical team, who have undergone enhanced vetting, and whose usage of such interfaces is governed by our strict policies, is logged, and monitored.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
For privileged access to our back end systems we utilise physical tokens as part of our authentication process for added security.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We recognise that our secure software service forms just one part of our business and that it is essential our entire organisation maintains the same high standard of Information Security best practice and awareness. We maintain a dedicatedInformation Security function and a comprehensive set of policies, guidelines and training for all staff. All are updated regularly and embedded company wide and all are covered by our ISO 27001 certification. A full list of the relevant areas covered by our policies is below. More details are available upon request. • InformationGovernance & Security Policy Overview • HumanResources • Firewall and Networking • WIFI • Penetration testing • Vulnerability management •Information Security Incident Management • RiskManagement • Access Control & AccountManagement • Business Continuity & Crisis &Disaster Recovery • Data Protection • InformationClassification & Handling • Software & Development Lifecycle • Internal Audit and Review• Viruses & Malware • Internet & Email AcceptableUse • Mobile Computing & Teleworking • PhysicalSecurity • Removable Media • Whistleblowing
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service changes are tracked, either through code control for software and infrastructure changes (GIT) or through management processes for service and support changes.

All proposed changes are subject to risk assessment before work begins, those deemed to affect or potentially affect information security are escalated to our Information Security Committee and, if needed, put to an internal working group or external experts for review of the plan and potential impact.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We subscribe to relevant industry feeds for zero day vulnerabilities and patches for all technologies in our stack.

We prioritise the assessment and application of these patches to ensure we stay up to date. Our infrastructure also allows us to hot swap clients to newly patched systems with zero downtime.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We have a number of monitoring systems that provide automated alerts if a potential vulnerability or compromise is detected. This includes firewalls, malware scanners and intrusion detection systems. If an alert is triggered the support team respond right away to investigate. If an alert is confirmed as a compromise we quarantine the affected systems pending investigation, form a working team to prioritise our containment and resolutions actions and immediately notify any affected clients.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management response is governed by our ISO 27001 incident management policy which defines how we respond to common events, depending on severity. Our support team also has a range of operating procedures to govern response to support issues.

We track all support issues and incidents. Any incident that affects security is tracked in more detail in our incident tracker and receives a full follow-up retrospective from our information security committee to ensure it is properly closed and lessons learnt.

We provide incident reports to clients via their preferred channel established at onboarding, normally by email.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Wednesday 27 August 2025
What the ISO/IEC 27001 doesn’t cover
No exclusions in Statement of Applicability
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
545129dc-4ba8-41bc-838f-cc2a3f0261da
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
40eb4bf6-f5b3-44fd-9281-47113359481e
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at solutions@boardintelligence.com. Tell them what format you need. It will help if you say what assistive technology you use.