Skip to content

Compliance answers

Admin, Compliance (/admin/compliance).

Every answer on a departmental vendor assessment was already knowable from somewhere in Plugboard and not answerable from anywhere in it. A school filling in the form had to email and ask, which is slow for them and unnecessary for us, because the deployment already knows.

This screen states it.

Where the data is held. The region, its location and its residency statement. Read from local configuration, not by calling home, so it still answers while cut off from everything, including during the incident where somebody is most likely to ask.

What each connector sends, and where. Stated per category, because the question is about the kind of data leaving, and a school swapping Jamf for Intune has not changed the answer.

CategoryWhat leaves
MDMDevice serial numbers, models, assignment and compliance state
SISStudent and staff names, year levels, identifiers and email addresses
DirectoryNames, usernames, email addresses and group membership
EmailMessage content and recipient addresses
SMSPhone numbers and message content
TicketingTicket subject, body and requester details
WarrantySerial numbers
Repair vendorSerial numbers, fault descriptions and contact details
SecurityDevice identifiers and application approval requests
CRMAccount and contact details
PrintingUsernames, card numbers and print balances
AIWhatever you ask the assistant, to a model you host

Only the connectors you have actually enabled are listed, so the answer is about your deployment rather than about the product.

Which connectors are in demo mode. Because a connector in demo mode is not sending anything anywhere, and a connector you thought was in demo mode and is not, is a finding.

Retention settings. How long the audit log is kept, and what your erasure policy is set to.

Whether vendor access is enabled.

The switch that matters most on this page.

Vendor access to a managed deployment is off by default, time-bound when granted, and audited. Every action a vendor engineer takes appears in your own audit log alongside everything else, attributed to them.

You can disable it outright from here. With it disabled we cannot reach your data at all.

That is a real trade rather than a free win. Some kinds of support become “here is what to look for” rather than “we looked”. Schools that make this choice usually make it deliberately, and write it down internally, so the person raising a support ticket in eighteen months knows why the answer is shaped the way it is.

Self-hosted deployments have no vendor access path at all, and the screen says so.

Screenshot this page. It answers, in the assessment’s own terms:

  • Where is the data held
  • Is it transferred outside that jurisdiction
  • Which sub-processors receive what
  • How long is data retained
  • Can the vendor access our data
  • What is the deletion process

The parts an assessment asks that this page cannot answer are the ones about your own configuration: who at your school has which permissions, and whether you have restored a backup. Those are roles and backups.

Two different clocks.

Audit retention is operational and set by you. Longer is better for investigation and worse for disk and for privacy. See audit and retention.

Erasure is the process for removing a person’s records on request. Plugboard supports it as a first-class operation, not a manual database edit. An assessment will ask how deletion works, and “by hand” does not describe a process.

The in-product assistant runs against a model you host, through the Ollama connector. Nothing is sent to an external AI provider. Without a model configured, the assistant still works using a built-in offline command engine.

That guarantee is about the assistant. It does not extend to a third-party MCP client you have chosen to connect, because that client hands tool results to whatever model it uses.

If that distinction matters to your assessment, and it usually does, state it this way: the product sends nothing to an external AI service; connecting an external MCP client is a decision you make, and you should scope API keys accordingly.