SupplyBoard

Your your data stays protected at SupplyBoard.

SupplyBoard runs on Amazon Web Services. We add the application controls that decide who can access your accounts, company records, and manufacturing files.

SupplyBoard security — private manufacturing files and accounts protected on managed cloud infrastructure.

Built on Amazon Web Services

SupplyBoard runs on Amazon Web Services (AWS), a widely used cloud platform that hosts applications, data, and files for organizations around the world. AWS provides the infrastructure. SupplyBoard provides the application controls that decide who can access your accounts, company records, and manufacturing files.

We use AWS in a deliberate way:

  • Application hosting. SupplyBoard’s websites and APIs run on managed AWS compute services, so the platform is delivered from professionally operated cloud infrastructure rather than from unmanaged local servers.
  • Private databases. Company records, accounts, quotes, and operational data are stored in managed AWS databases. These databases are not open to the public internet. Only approved SupplyBoard services can connect to them.
  • Private file storage. CAD files, drawings, and generated previews are kept in private AWS object storage, separate from the public website. Access is granted through authorized, time-limited workflows.
  • Public website delivery. Public pages and static assets can be delivered through AWS content delivery network, which helps the public site load quickly and reliably. Private customer files remain under their own access rules and are not treated as public website content.
  • Access control. AWS identity and network controls limit which SupplyBoard systems and personnel can reach production infrastructure. Access is granted according to operational need.
  • Secrets management. Database credentials and other sensitive operational values are stored in AWS-managed secret systems, not in the public website or in source code.
  • Monitoring and recovery. AWS monitoring, health checks, and backups help us operate the platform reliably, investigate issues, and restore supported systems when needed.

Using AWS gives SupplyBoard a production-grade foundation: secure hosting, private storage, controlled access, and operational visibility. It does not replace SupplyBoard’s own authentication, company permissions, or file-handling rules. Those application controls work together with AWS so that your data is protected both in the cloud infrastructure and inside the SupplyBoard platform.

AWS hosts and operates infrastructure used by SupplyBoard. That does not mean AWS certifies SupplyBoard. It means your work runs on managed, industry-standard cloud services, with SupplyBoard responsible for how accounts, files, and company data are accessed on top of them.

What the platform is protecting

Not all data is treated the same. The platform separates:

  • Public information. Marketing pages, published supplier profiles, and approved directory content.
  • Confidential business data. Accounts, company memberships, RFQs, quotes, orders, messages, and internal notes.
  • Sensitive technical data. CAD files, drawings, manufacturing specs, geometry, and generated previews. This is treated as customer intellectual property.
  • Personal information. Names, emails, phone numbers, login activity, and similar identifiers.
  • Secrets. Passwords, API keys, signing keys, and similar credentials. These are never meant to appear in source code, frontend builds, or logs.

How accounts stay secure

Private areas of SupplyBoard are available only after we verify that you are who you say you are. We operate our own account and session controls, so access to your workspace is managed by SupplyBoard rather than left open to the public internet.

For users and companies, that means:

  • Your password is never stored in a readable form. We store a secure one-way version of it, so even SupplyBoard cannot look up your actual password.
  • Repeated login attempts are limited. This helps protect accounts against password guessing.
  • Your signed-in session is time-limited and refreshed in a controlled way. If something looks like a stolen session being reused, SupplyBoard can sign that account out of active sessions.
  • Sign-in details are kept in protected browser cookies that cannot be read. In production, those cookies are sent only over encrypted SSL connections and only for SupplyBoard domains.
  • If you choose to sign in with Google, we receive only the basic identity information needed to create or recognize your account. We do not request access to your Gmail.
  • Login errors are written carefully so they do not reveal whether an email address already has an account.
  • Administrative access is verified against live SupplyBoard records, not assumed from a saved login claim.

We also stop other websites from quietly acting in your name while you are signed in. When your browser session is used to change something, update a profile, submit a quote, or manage company settings, SupplyBoard checks that the request really came from you.

CAD files and quoting are protected with a separate access layer. A normal website login cannot be used to reach internal quoting systems, and a guest or customer session cannot call those private services. Only the authorized SupplyBoard workflow that needs to process your request is allowed through.

The result is straightforward: your account is gated, your session is protected, and private manufacturing work stays behind controls that public visitors never receive.

How files are protected

Your CAD files, drawings, and manufacturing attachments are private and secure. They are not listed in the supplier directory, not shown on public company pages, and not used as marketing material. A file is made available only to its owner (user or company) and, with your consent, to SupplyBoard services that need it to quote, review, or fulfil the work you requested.

From upload to finished quote, the file stays inside a controlled path:

  1. We check every upload. SupplyBoard verifies the file type, size, and related details before it is accepted. Unsupported files are rejected. Guest uploads have a lower size limit; signed-in uploads can be larger, within set limits.
  2. Files are stored privately. Original designs and anything generated from them — previews, 3D views, and analysis results — are kept in private storage, separated by company or quoting session. They are not stored with public website assets.
  3. Access is temporary. When an authorized person or service needs to upload or download a file, SupplyBoard can issue a time-limited link instead of a permanent public URL. Those links expire. Files are not left sitting behind guessable web addresses.
  4. Processing is tightly controlled. Viewing, conversion, and quoting analysis are performed only by the SupplyBoard Studio and other SupplyBoard services required for that job. Those services run with limited access, time limits, and cleanup of temporary working files. File contents are not written into ordinary system logs.
  5. Guest quotes stay separate. If you upload a file without creating an account, that file belongs to that quoting session. Signing in later does not quietly move it into another session.
  6. Quoting happens behind the scenes. The systems that analyze a part and calculate a price are not open to public browsers or ordinary logins. Only authorized SupplyBoard services can request that work, and they can do so only for the company or session the file actually belongs to.

Anything created from your file is protected the same way as the original: stored privately, available only with authorization, and kept out of the public directory.

In short, your designs stay yours. They are used to provide the service you asked for, not to publish, promote, or share with any third parties.

How SupplyBoard Vega protects machine data

SupplyBoard Vega is built for factory data, not for the public directory. Temperature readings, machine status, and related monitoring information belong to the company that owns the equipment. They are not published on supplier profiles, and they are not visible to unrelated companies.

Shop-floor devices, company dashboards, and SupplyBoard administration each use a separate access path. A Vega sensor or factory agent does not log in as a person. It uses credentials issued for that installation, stored in a protected form. A device can send readings only while it is active, and only for the machine and company it is assigned to. If a device is deactivated or its credentials are changed, it can no longer submit data. Incoming readings are checked before they are stored, and a device cannot attach itself to another company’s equipment.

Monitoring is not permanently open just because a sensor is installed. It follows the company’s partner relationship and contract status. Readings are accepted only when access is allowed for that machine. If monitoring is paused, removed, or ended, new data is not collected, and live telemetry is shown only while access is active.

The business dashboard is limited to your organization. Signed-in users see their own machines, not other customers’ factories, and live data is available to the people responsible for operations, typically owners, admins, and operators, not every employee with a SupplyBoard login. Company users cannot reach SupplyBoard’s internal Vega administration tools.

Vega runs on the same AWS foundation as the rest of SupplyBoard, with encrypted connections, private databases, managed secrets, and operational monitoring. Factory readings are stored in dedicated Vega data stores and stay connected to the correct company, without mixing one customer’s machines into another’s view.

In practice, your shop-floor data is collected only from authorized devices, stored privately, shown only to authorized people in your company, and stopped when access is no longer active. Vega is an operational tool for your team, not a public feed, and not a path into another company’s factory.

How safety is maintained over time

Protecting a file or account does not stop after it is saved. SupplyBoard keeps security in place while your data is stored, used, and eventually retained or removed.

We watch the platform for unusual activity and investigate issues when they appear. Supported systems are backed up so information can be restored if something goes wrong. Changes to the live platform go through review and testing first, so unreviewed updates are not simply pushed into production.

If a security concern is identified, we have a defined response: contain the issue, close off affected access, protect evidence, determine what was involved, fix the problem, and notify people when we are required to do so.

If you believe you have found a vulnerability, please report it privately to support@supplyboard.io. Do not publish sensitive details in public channels.

We keep information for as long as it is needed to operate the platform, meet contractual and legal obligations, and protect against fraud or abuse. If you make an authorized request to delete data, we handle it according to those requirements. Some records may remain for a period of time in backups or where the law requires us to keep them, so deletion is not always immediate.

The goal is continuity: your data stays protected not only at upload, but throughout the time SupplyBoard is responsible for it.

SupplyBoard highly values your data protection and security.

Protecting your accounts, company records, manufacturing files, and factory data is treated as a core operating requirement, not a separate add-on.

The controls on this page work together with our privacy and legal terms so you can review how information is collected, used, and kept.

Please review our privacy policy and terms and conditions.