Third Party Index

Snapshot 40174

Document
Security page
URL
https://myviewboard.com/white-paper/security
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
129084 bytes
SHA-256 (raw)
dbf6ca1ba29862e2dc7c538b88d2f3ef572f5d85bd32b76ea03dcb9722beca85
SHA-256 (normalized text)
adcf226004bb82b5f460a6ae2ea0a9bf8ae58a8578194a37386af84edad35e1b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

myViewBoardâ„¢ Security Whitepaper
Date: May 31, 2026
1. Introduction
Security and privacy are fundamental components of myViewBoardâ„¢ in the design, development, and delivery of our services. This whitepaper outlines how myViewBoardâ„¢ ensures the highest level of data security for enterprises and educational institutions through the Security Development Lifecycle (SDL) approach, advanced encryption technologies, and global redundancy architectures.
2. myViewBoardâ„¢ implements the Security Development Lifecycle method to safeguard your security
Security Development Lifecycle (SDL) is a set of activities and milestones that can drive high-quality security outcomes in the development of products and services. It can be divided into 4 distinct sections: Architecture and Design, Implementation, Validation, and Software Release. A review is conducted after each stage has been completed.
In myViewBoardâ„¢, we have been using the SDL approach during our monthly releases since our launch in 2018, and we continuously update and refine our services based on our monthly findings.
During the development stage of the lifecycle, we never use production data for testing or development. Your data is accessed only when an order from the executive team requires it for a specific purpose.
3. Compliance & Certifications
To demonstrate our commitment to high-standard security protection, myViewBoardâ„¢ and the ViewSonic Cloud Platform have achieved multiple third-party international security certifications:
SOC 2 Type I Report: Independently audited by Deloitte & Touche as of December 31, 2025, this report verifies that myViewBoard's internal controls meet the highest industry benchmarks for Security and Privacy.
Google CASA Tier 2 Validation: Authorized by the App Defense Alliance and assessed by the independent lab DEKRA, this validates that the myViewBoard application architecture fully complies with 14 essential security requirements. From Session Management to Architecture Security, this assessment proves that our platform delivers enterprise-grade protection for high-complexity API and web-based environments.
CSA STAR Registry: The myViewBoard cloud service is listed in the CSA STAR Registry and has completed the Consensus Assessment Initiative Questionnaire (CAIQ), demonstrating radical transparency in our cloud security practices.
4. Infrastructure & Global Network Architecture
myViewBoard utilizes Amazon Web Services (AWS) as its underlying infrastructure to build a highly available global network:
Multi-Region Hub-and-Spoke Architecture: The system is deployed across multiple global AWS regions, including Virginia, Singapore, Frankfurt, Tokyo, Canada, and Sydney. Virginia (us-east-1) and Frankfurt (eu-central-1) act as core hub nodes, establishing multiple connections with other regions to ensure high network availability and cross-region redundancy.
Strict VPC Subnet Segregation: Each deployment region implements strict network segregation, including Public Subnets, Private Subnets (App Layer), Database Subnets, ElastiCache Subnets, and Intra Subnets, blocking unauthorized cross-layer access through logical isolation.
N+1 Redundancy Design: Databases and core services use an N+1 redundancy architecture to ensure data security and minimize system downtime, thereby promoting high availability.
5. Data Protection & Privacy
"Zero-Persistence" Architecture & Third-Party Integration: When users link myViewBoard to third-party cloud drives like Google Driveâ„¢ or Microsoft OneDriveâ„¢, the system securely indexes and stores "File Metadata" (such as file names and directory structures) in the backend to optimize cross-platform search. This metadata is encrypted at rest with AES-256 via AWS KMS and stored in private VPC subnets with no public network route. However, for the actual "File Content" (e.g., documents containing sensitive student data), the system employs "Direct Local Rendering" technology. File content is never routed through, cached, or stored on myViewBoard servers; it is accessed directly by the client-side application via official APIs.
Data Encryption in Transit and at Rest: All data in transit over public networks is protected by TLS 1.2/TLS 1.3, using strong cipher suites such as AES-256-GCM for confidentiality and integrity, with SHA-256 for secure hashing and signature verification. All static customer data at rest is protected using AES-256 encryption.
Logical Data Segregation: We enforce logical segregation of customer data, ensuring that each organization's data operates in an isolated environment and that cross-entity access is strictly prevented.
Data Residency & Compliance: myViewBoard's database redundancy architecture is built solely on the availability of individual geographic regions. To ensure compliance with global data sovereignty and stringent privacy regulations, customer data is stored and processed locally within the customer's dedicated AWS region, such as Virginia, Frankfurt, Singapore, Tokyo, Canada, or Sydney. For example, customer data in the European Union is exclusively hosted in the Frankfurt region (eu-central-1). This ensures that all data processing and static storage are strictly confined within that specific jurisdiction, strictly prohibiting any unauthorized cross-border data transfers.
In-Region N+1 Redundancy Architecture: While ensuring data residency within the designated region, the underlying system operates under an N+1 redundancy model. This architectural design supports hot-swapping between machine nodes, ensuring the absolute security of customer data within the local database and facilitating a seamless transition during hardware anomalies to promote up to 99.999% service availability.
Data De-identification & Backup Lifecycle Overwrite: When handling sensitive data, the system uses tokenization and data masking to prevent reverse identification. To prevent deleted data from being restored into the production environment, the system implements processing restrictions to isolate it until it is naturally overwritten or destroyed during standard backup rotation cycles.
Automatic Erasure of Temporary Data: When a user logs out, closes the application, switches users, or reaches the system idle time, all temporary files and profile information are immediately erased from the application.
Safeguarding Personal Information: ViewSonic is committed to the ethical collection and processing of your personal data. We do not sell your personal information, nor do we share it with third parties for marketing or unauthorized commercial purposes. Access to your data is strictly limited to authorized personnel and vetted sub-processors (e.g., our secure cloud infrastructure providers) necessary for delivering myViewBoard services. All engaged third parties are bound by strict Data Processing Agreements (DPAs) and confidentiality obligations to ensure your data is handled securely and in compliance with global privacy standards. For comprehensive details on our data collection practices, usage policies, and GDPR compliance, please refer to our Privacy Policy.
6. Access Control & Identity Management
Zero-Trust & Authentication: myViewBoard supports two secure authentication models. Users can authenticate using local accounts (where passwords are salted and hashed using bcrypt; plaintext passwords are never stored), or via Federated Single-Sign-On using trusted Identity Providers (IdPs) such as Google and Microsoft. In Single-Sign-On mode, all credential verification and Multi-Factor Authentication (MFA) remain fully under the IdP's control, ensuring zero password exposure to our systems.
Secure Cloud Integrations via OAuth 2.0: When linking third-party cloud drives such as Google Driveâ„¢ or Microsoft OneDriveâ„¢, the application uses the OAuth 2.0 authorization framework. The backend database stores only encrypted tokens (AES-256 at rest) required to maintain delegated access. The system never requests, transmits, or stores users' third-party account credentials, guaranteeing the security of external data.
Operational Access: All internal operations personnel accessing production cloud resources are strictly bound by the Principle of Least Privilege. Accessing production resources requires Multi-Factor Authentication (MFA) and domain credentials.
Inactive Account Removal: The system features an automated auditing mechanism for domain-level accounts in the production environment. Accounts are automatically disabled and removed after exceeding a specified period of inactivity (e.g., 90 days), enforcing strict access hygiene.
7. Vulnerability Management & Continuous Monitoring
Proactive Threat Detection: The system deploys AWS-native monitoring tools (including CloudWatch, GuardDuty, and Security Hub) and a Web Application Firewall (WAF) to defend against DDoS attacks and common web exploits, such as SQL injection and cross-site scripting.
Open-Source Vulnerability Control & Patching SLA: ViewSonic maintains a strict vulnerability management program for open-source technologies and third-party packages, utilizing enterprise-grade security tools (such as Qwiet AI and Nexus) within our CI/CD pipeline. All vulnerabilities classified as Critical or High risk undergo an immediate risk assessment. Based on the severity and potential impact, security patches and compensating controls are developed, tested, and deployed promptly to ensure the continuous security of our services.
Penetration Testing: The internal security team regularly conducts vulnerability scans and commissions external professional agencies to perform annual system penetration testing to validate the effectiveness of our defense mechanisms.
8. Streaming Security
myViewBoard utilizes WebRTC technology for audio/video streaming and screen sharing. This open standard framework provides peer-to-peer direct communication without requiring onerous plugins and downloads, lowering the risk of malware:
DTLS Encryption: All transmitted data is encrypted using Datagram Transport Layer Security (DTLS) to prevent eavesdropping or data tampering.
SRTP: Video and audio data are safeguarded by the Secure Real-time Transport Protocol (SRTP), ensuring utmost privacy for user communications.
9. Incident Handling
myViewBoard has a well-established incident handling mechanism, categorizing risks into four levels:
Critical: Indicates a risk of data leakage or a full service impact. The Virtual Incident Response team and senior management intervene immediately, and standard operating procedures (SOPs) are updated upon resolution.
High: Indicates a quality of service impact (e.g., broken cloud storage access). The incident response team engages immediately and provides daily progress reports to management until the issue is resolved.
Medium: Minor impact on services without affecting daily operations. Remediated immediately or scheduled for the next monthly release patch.
Low: Issues that do not affect service delivery or business operations, handled through regular issue-tracking procedures.
10. Resiliency of myViewBoardâ„¢
myViewBoardâ„¢ considers not only the confidentiality and integrity of our services but also their high availability. To ensure operational resilience and rapid recovery during critical disruptions, we maintain a comprehensive Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) built upon a modern, automated recovery architecture.
Prioritized and Automated Recovery Strategy: Our disaster recovery framework categorizes business processes to ensure critical services are prioritized and restored effectively. Instead of relying on manual infrastructure reconstruction, our recovery strategy is driven by advanced automation:
Stateless & Frontend Services: Managed entirely via Infrastructure-as-Code (IaC) utilizing tools like Terraform and Terragrunt. These network and frontend components are engineered to be rapidly redeployed directly from version control, eliminating the dependency on traditional data backups.
Core Applications & Confidential Data Services: Architected for resilient failover, our core web services and authentication mechanisms rely on automated scaling and isolated disaster recovery environments to restore transaction capabilities efficiently.
Robust Data Protection Mechanisms: We enforce rigorous data protection standards designed to minimize potential data loss across our global infrastructure:
Database & Object Storage Resilience: Critical data stored in relational databases (RDS) and highly durable object storage (S3) utilizes scheduled snapshot mechanisms and cross-region replication strategies. This ensures that point-in-time restoration can be executed securely within an isolated Disaster Recovery (DR) account.
Cross-Account Isolation Recovery Environment: In the event of a severe regional failure, our recovery workflows are designed to bypass localized infrastructure faults. By executing automated IaC scripts, the core AWS environment (including VPC, ECS, and databases) can be systematically rebuilt within an isolated DR account and a secondary region. This approach maintains strict logical network separation and ensures the integrity of the recovery process.
Continuous Resiliency Enhancement: System resiliency is an ongoing process of continuous improvement. We actively perform Multi-AZ failover evaluations and schedule full-scale cross-account disaster recovery live exercises to systematically validate and optimize our automated recovery capabilities. Furthermore, our engineering roadmap includes implementing cross-cloud redundancy for our source code repositories to proactively eliminate potential single points of failure within our CI/CD pipeline.
11. Complementary User Entity Controls (CUEC)
Under the SOC 2 Shared Responsibility Model, system security is a collaborative effort. User entities (customers) are responsible for implementing the following Complementary User Entity Controls (CUECs) to ensure the integrity of the overall security environment:
Contractual & Policy Compliance: User entities are responsible for understanding and complying with their contractual obligations under the ViewSonic Service Agreement and Terms of Service.
Administrative Contact Maintenance: User entities are responsible for promptly notifying ViewSonic of any changes to designated administrative or technical contact personnel.
Identity & Access Management: User entities are responsible for managing and reviewing the lifecycle of their users' access, including timely provisioning and de-provisioning of accounts upon personnel changes.
Authorized Change Approval: User entities are responsible for maintaining and providing a list of authorized personnel empowered to approve changes to security configurations or data integration settings.
Incident Reporting: User entities must report any suspected or actual security incidents, such as compromised user credentials or unauthorized data access, to the ViewSonic Security Team within the agreed timeframe.
Endpoint & Network Security: User entities are responsible for the security of their physical hardware and local network environments used to access myViewBoard services, including OS patching and firewall configurations.
Business Continuity Planning: User entities are responsible for developing their own internal contingency plans to maintain operations if the myViewBoard service is unavailable.
Appendix A: Network Requirements
myViewBoardâ„¢ applications need the following ports available for your system to communicate with ours:
TCP Port 443 (HTTPS): outbound
UDP and TCP port 3478 bidirectional to the WebRTC servers
UDP Ports 49,152 – 65,535 (RTP/sRTP/RTCP) bidirectional to the WebRTC servers. These ports are optional; if blocked, media will be proxied using TURN on port 3478.
The above ports are the minimum requirements for linking our service to your organization and ensuring its availability when you need it.
Our client software also needs to add or make modifications to the following system attributes and configurations (such as registry entries, firewall settings, digital certificates, kernel-mode drivers, and browser plugins):
Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\ViewSonic\vBoard (WhiteBoard for Windows)
Services:
The following are uses of cryptography:
Hashing Algorithms: SHA256
Public-Key Algorithms: RSA-2048
SSL Schemes: TLS 1.2
Appendix B: Subservice Organizations
Under the SOC 2 Shared Responsibility Model, the myViewBoard cloud platform relies on the following key subservice organizations to support its cloud infrastructure, identity management, and software development lifecycle. Through its Third-Party Risk Management (TPRM) program, ViewSonic regularly reviews the independent third-party audit reports (e.g., SOC 2 reports) of these providers to obtain reasonable assurance regarding the design and operating effectiveness of their security controls.
Amazon Web Services (AWS)
Core Service Description: AWS provides myViewBoard with cloud infrastructure, including hosting, data storage, network security, and system monitoring. Specific integrations include Amazon Relational Database Service (RDS), Amazon Simple Storage Service (S3), Web Application Firewalls (WAF), and security monitoring tools such as CloudWatch.
Locations of Data Processing and Storage: To ensure strict adherence to Data Residency requirements and global privacy regulations, AWS supports multi-region deployments. Customer data processing and storage are strictly confined to their designated regions, including Virginia (US), Frankfurt (Germany), Singapore, Tokyo (Japan), Canada, and Sydney (Australia).
Complementary Subservice Organization Controls (CSOCs): As the Infrastructure as a Service (IaaS) provider, AWS assumes direct responsibility for the physical and environmental security of its data centers, hardware lifecycle management, and the protection of the underlying network infrastructure (e.g., perimeter firewalls).
Microsoft Corporation
Core Service Description: myViewBoard utilizes critical Microsoft cloud services to support identity security and the software development lifecycle:
Microsoft Entra ID: Provides centralized identity authentication and Identity and Access Management (IAM) services.
Azure DevOps: Serves as the core platform for source code management, Continuous Integration/Continuous Deployment (CI/CD) pipelines, and controlled release processes.
Complementary Subservice Organization Controls (CSOCs): Microsoft is responsible for the underlying security architecture of its PaaS/SaaS offerings. For Azure DevOps, Azure manages the encryption of underlying secrets, environment backups, and Point-in-Time Restore (PITR) capabilities for relational databases.
GitHub (GitHub, Inc.)
Core Service Description: GitHub is utilized for source code management, CI/CD workflows, and controlled version release mechanisms. It can leverage native security suites, such as GitHub Advanced Security, to automatically scan for exposed secrets, identify known vulnerabilities in open-source dependencies, and perform real-time static code analysis during the development workflow.
Locations of Data Processing and Storage: The physical server locations where organizational source code, test data, and metadata are processed and stored must be independently verified in accordance with the organization's GitHub Enterprise agreement to ensure compliance with GDPR cross-border data transfer requirements.
Complementary Subservice Organization Controls (CSOCs): GitHub is responsible for the physical and environmental security, network perimeter protection, and system backups of its underlying SaaS infrastructure. Under the shared responsibility model, ViewSonic is responsible for implementing strict logical access controls to GitHub repositories, mandating appropriate authentication mechanisms for developers, protecting account credentials and secrets, and conducting periodic access reviews.
We use cookies to deliver you the enhanced website experience. Please give your consent by accepting our Privacy Policy.