Compliance answers
Admin, Compliance (/admin/compliance).
Every answer on a departmental vendor assessment was already knowable from somewhere in Plugboard and not answerable from anywhere in it. A school filling in the form had to email and ask, which is slow for them and unnecessary for us, because the deployment already knows.
This screen states it.
What it tells you
Section titled “What it tells you”Where the data is held. The region, its location and its residency statement. Read from local configuration, not by calling home, so it still answers while cut off from everything, including during the incident where somebody is most likely to ask.
What each connector sends, and where. Stated per category, because the question is about the kind of data leaving, and a school swapping Jamf for Intune has not changed the answer.
| Category | What leaves |
|---|---|
| MDM | Device serial numbers, models, assignment and compliance state |
| SIS | Student and staff names, year levels, identifiers and email addresses |
| Directory | Names, usernames, email addresses and group membership |
| Message content and recipient addresses | |
| SMS | Phone numbers and message content |
| Ticketing | Ticket subject, body and requester details |
| Warranty | Serial numbers |
| Repair vendor | Serial numbers, fault descriptions and contact details |
| Security | Device identifiers and application approval requests |
| CRM | Account and contact details |
| Printing | Usernames, card numbers and print balances |
| AI | Whatever you ask the assistant, to a model you host |
Only the connectors you have actually enabled are listed, so the answer is about your deployment rather than about the product.
Which connectors are in demo mode. Because a connector in demo mode is not sending anything anywhere, and a connector you thought was in demo mode and is not, is a finding.
Retention settings. How long the audit log is kept, and what your erasure policy is set to.
Whether vendor access is enabled.
Vendor access
Section titled “Vendor access”The switch that matters most on this page.
Vendor access to a managed deployment is off by default, time-bound when granted, and audited. Every action a vendor engineer takes appears in your own audit log alongside everything else, attributed to them.
You can disable it outright from here. With it disabled we cannot reach your data at all.
That is a real trade rather than a free win. Some kinds of support become “here is what to look for” rather than “we looked”. Schools that make this choice usually make it deliberately, and write it down internally, so the person raising a support ticket in eighteen months knows why the answer is shaped the way it is.
Self-hosted deployments have no vendor access path at all, and the screen says so.
Using it for an assessment
Section titled “Using it for an assessment”Screenshot this page. It answers, in the assessment’s own terms:
- Where is the data held
- Is it transferred outside that jurisdiction
- Which sub-processors receive what
- How long is data retained
- Can the vendor access our data
- What is the deletion process
The parts an assessment asks that this page cannot answer are the ones about your own configuration: who at your school has which permissions, and whether you have restored a backup. Those are roles and backups.
Erasure and retention
Section titled “Erasure and retention”Two different clocks.
Audit retention is operational and set by you. Longer is better for investigation and worse for disk and for privacy. See audit and retention.
Erasure is the process for removing a person’s records on request. Plugboard supports it as a first-class operation, not a manual database edit. An assessment will ask how deletion works, and “by hand” does not describe a process.
The AI row, read twice
Section titled “The AI row, read twice”The in-product assistant runs against a model you host, through the Ollama connector. Nothing is sent to an external AI provider. Without a model configured, the assistant still works using a built-in offline command engine.
That guarantee is about the assistant. It does not extend to a third-party MCP client you have chosen to connect, because that client hands tool results to whatever model it uses.
If that distinction matters to your assessment, and it usually does, state it this way: the product sends nothing to an external AI service; connecting an external MCP client is a decision you make, and you should scope API keys accordingly.