OnBoard AI Security Overview

Josh Patton
Josh Patton
  • Updated

OnBoard’s AI features help organizations find information, prepare content, and understand meeting materials more efficiently. This article explains how OnBoard processes and protects customer content when providing its AI features.

NOTE: This article describes OnBoard features and provides general information. It does not provide legal advice. Your organization should determine how its own legal, regulatory, security, and policy requirements apply to its use of AI.

OnBoard AI Features

What OnBoard AI Features are Available?

OnBoard AI includes several built-in features:

  • AI Assist allows users to ask questions about meeting and resource information they have permission to access.
  • AI Agenda helps administrators prepare draft meeting agendas.
  • AI Minutes helps administrators prepare draft meeting minutes using temporary meeting recordings and transcripts.
  • AI Meeting Insights provides summaries and analyses based on temporary meeting recordings and transcripts.
NOTE: Available features and configuration options may vary by organization and OnBoard package.

Data Usage and AI Training

Is My Board Data Used to Train AI?

No. OnBoard and its service providers are contractually prohibited from using customer content to train AI models.

OnBoard uses OpenAI models deployed through Microsoft Azure OpenAI Service to provide core AI capabilities. OnBoard uses the models only to generate responses. Customer content is not used to train or improve the models.

For select features, OnBoard uses service providers to provide specialized functionality. These providers are also contractually prohibited from using customer content to train models.

These restrictions apply to all customer content processed through OnBoard’s AI features, including:

  • Board materials
  • Prompts
  • Recordings
  • Transcripts
  • AI-generated outputs

Data Processing and Storage

Where Does My Data Go When I Use OnBoard AI?

OnBoard uses contracted service providers to deliver certain AI functions. Customer data may be processed by these providers only as needed to provide the requested feature, and for no other purpose of their own.

OnBoard and its providers are contractually restricted from using customer content to train AI models or for independent purposes.

Additional protections include:

  • Data is transmitted over encrypted connections.
  • Customer content does not enter the general training pipelines used by public AI services.
  • OnBoard AI does not export customer content to consumer ChatGPT accounts or browser extensions.

Conversation Data and AI Activity Records

What Conversation and Activity Data Does OnBoard Save?

OnBoard saves AI Assist conversation history so users can revisit previous conversations, until the user deletes it. These conversations are not used to train AI models.

Users can:

  • Review their saved conversations.
  • Return to a previous conversation.
  • Delete their own conversations.

AI Assist conversations are not visible to other users in your organization. No other user of your OnBoard account can open or read their prompts and conversation history, including Admins, Creators, Members, and Global Admins.

Separately, OnBoard maintains an activity log that records:

  • Who used an AI feature
  • Which AI feature was used
  • When it was used

For example, an activity entry may state, “User interacted with AI Assist.” The activity log does not include the user’s questions or AI Assist’s answers. Only a Global Admin can view the activity log. Admins, Creators, and Members cannot access it.

Other AI features may create similar activity records, such as when someone views an AI-generated meeting book summary or saves or discards an AI-generated agenda.

Permissions and Access Control

Can OnBoard AI Show Content I Cannot Access?

OnBoard AI uses existing OnBoard permissions when finding and presenting information. AI responses draw only from content the signed-in user has permission to access. 

For example:

  • AI Assist does not use a restricted document to answer a user who cannot access that document.

Permissions still depend on how meetings, resources, documents, and other OnBoard content have been configured.

Human Oversight and Accountability

Should AI-Generated Content be Reviewed?

Yes. AI-generated content may contain errors, omit context, or require additional editing. Users should review and validate AI outputs before:

  • Sharing them with others
  • Relying on them for decisions
  • Incorporating them into organizational materials

How Should Draft Agendas and Minutes be Handled?

AI Agenda and AI Minutes help users prepare drafts.

The organization reviews, edits, and approves those drafts through its usual processes. OnBoard does not determine whether content is final, approved, or an official organizational record.

How Should Other AI Outputs be Handled?

AI Assist and AI Meeting Insights provide informational outputs. Users should evaluate those outputs and check the available source material before relying on them.

AI can make work more efficient, but people remain responsible for reviewing and using its outputs appropriately.

Feature Controls

Can Administrators Turn off OnBoard AI Features?

Configuration options vary by feature. Administrators can manage some AI features directly, while other changes may require assistance from OnBoard Customer Support.

Which Features Can Administrators Manage Directly?

Administrators can directly enable or disable:

  • AI Minutes
  • AI Assist

When one of these features is disabled, users cannot access it. An administrator can enable it again later.

How are Other AI Features Managed?

Other AI features may require assistance from OnBoard Customer Support, including:

  • AI Agenda
  • AI Meeting Insights

To request a configuration change, submit a Support Ticket.

Data Security Standards

How Does OnBoard Protect Customer Data?

OnBoard maintains security controls across the platform, including:

  • Encryption in transit and at rest
  • Multi-Factor Authentication (MFA) support
  • Single Sign-On (SSO) capabilities
  • Role-based and permission-based access controls

Compliance certifications:

  • SOC 2 Type II – Security and availability auditing standard
  • ISO 27001 – Information security management standard
  • ISO 27701 – Privacy information management standard

Data Ownership and Privacy Roles

Who Controls How My Data is Used?

Your organization decides which available OnBoard AI features to use and how to use their outputs.

OnBoard and its contracted service providers process customer data to provide requested services under applicable agreements. Those service providers are restricted from using customer content to train AI models.

OnBoard does not independently determine how your organization uses AI-generated outputs.

AI Minutes and Recording Security

How are Recordings Handled for AI Minutes?

AI Minutes uses meeting recordings and transcripts to help administrators prepare draft minutes. Recording is optional and does not begin automatically.

How Does Recording Begin?

  • A Meeting Administrator configures the Recording Assistant for a supported remote meeting.
  • The Recording Assistant attempts to join the meeting at its scheduled time.
  • A meeting host must admit the Recording Assistant and allow it to record.
  • If the Recording Assistant is not configured and admitted, it does not record the meeting.

Who Can Access the Recording and Transcript?

Administrators of the meeting can access the recording and transcript.

Meeting Readers and Meeting Contributors cannot access the recording or transcript unless they are also administrators of that meeting.

How are Recordings Processed?

Recordings and transcription are handled by our contracted recording provider. That provider is prohibited from using customer recordings or transcripts to train AI models. OnBoard receives the finished transcript and uses it to produce your AI Minutes.

When are Recordings and Transcripts Deleted?

A Meeting Administrator may manually delete the recording, transcript, and outline. If they are not deleted earlier, OnBoard automatically deletes those materials 90 days after the meeting.

Your organization should determine whether its retention or preservation requirements apply before deleting these materials.

FAQs

Does OnBoard AI send my data to public AI tools?

  • OnBoard does not export customer content to consumer ChatGPT accounts or other public AI tools.
  • OnBoard uses contracted service providers to deliver certain AI functions. These providers are contractually restricted from using customer content to train models or for independent purposes.

Can I delete my AI Assist conversations?

  • Yes. You can delete your saved AI Assist conversations.

Can administrators restrict AI usage?

  • Yes. Administrators can manage certain features directly. Other configuration changes may require assistance from OnBoard Customer Support.

Is customer content used to train AI models?

  • No. OnBoard and its contracted service providers are prohibited from using customer content to train AI models.

Should I review AI-generated content?

  • Yes. Review AI-generated content and check the available source information before sharing it, relying on it for decisions, or incorporating it into organizational materials.

What happens to AI Minutes recordings?

  • AI Minutes recordings and transcripts are accessible to authorized Meeting Administrators. A Meeting Administrator may delete the recording, transcript, and outline manually. If they are not deleted earlier, OnBoard automatically deletes those materials 90 days after the meeting. 

Is customer data encrypted?

  • Yes. OnBoard encrypts customer data in transit and at rest.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.