Security & privacy

RelookBoard360 is built around a single rule: your operational data is never persisted by us.

Sign in

No operational data at rest

Work items, sprints, tickets and exports are analysed in your browser session and discarded. Our database holds only organisations, people, roles and configuration.

Memory-only credentials

API tokens live in the tab that you typed them into. They are attached to each proxied request and never written to storage, logs or caches.

Hardened read-only proxy

Live requests pass through a server proxy that allows public hostnames only, refuses internal and loopback addresses, and performs read operations exclusively.

Tenant isolation

Every configuration table enforces row-level security scoped to your organisation membership, checked on the server for each request.

Role-based access

Roles are stored separately from user profiles and evaluated server-side, so a persona cannot be elevated from the browser.

Deterministic analytics

Metrics, scores and forecasts are computed by explicit formulas over your data. Nothing is inferred, and no customer data is sent to a model.

What we do store

  • Organisation profile: name, code, timezone, branding and enabled modules.
  • People: email, name and role membership, so we can decide who may open which dashboard.
  • Preferences: thresholds, field mappings and dashboard layout choices.
  • Administrative audit events: who changed access or configuration, and when.

Ending a session, closing the tab or signing out destroys the in-memory dataset and any credentials it held.