// Security & data protection

Built like we have something to lose. Because you do.

BOSRAI runs your outreach from your own accounts and holds your pipeline data. Here is exactly how that data is protected โ€” in plain language, no theater.

Passwordless auth TLS everywhere Encrypted at rest Cookieless visitor tracking GDPR-aware by design

๐Ÿ”‘ No passwords to steal

Sign-in is magic-link only โ€” we never store a password, so there is no password database to breach, phish, or reuse. Sessions use short-lived tokens with rotating refresh credentials. Channel connections (Gmail, Microsoft, LinkedIn, WhatsApp, calendars) use OAuth or hosted authentication: your credentials are never typed into, seen by, or stored on BOSRAI. Revoke any connection with one click, any time.

๐Ÿ”’ Encryption, both directions

All traffic is TLS-encrypted in transit. At rest, your data lives in a managed PostgreSQL cluster (Supabase) with AES-256 encryption, continuous backups, and point-in-time recovery. Payments are processed entirely by Stripe โ€” card numbers never touch our servers, ever.

๐Ÿ‡ช๐Ÿ‡บ Visitor tracking that respects visitors

Our website-visitor lead feature was designed EU-safe from day one, because most tools in this category weren't: the snippet is cookieless, sets no identifiers in the browser, resolves companies only (never people), and raw IP addresses are never persisted โ€” only a salted one-way hash for deduplication. Home and mobile ISP traffic is deliberately discarded.

๐Ÿ“ฆ Your data is yours

Export your contacts, deals, and conversations at any time. When you delete your workspace, your data is deleted โ€” not archived into a "legitimate interest" black hole. We don't sell data, we don't train shared models on your pipeline, and your business knowledge (ICP, messaging, objection learnings) stays inside your workspace.

๐Ÿค– AI, scoped tightly

AI features run against leading model providers (Anthropic, Google) under their enterprise API terms โ€” API traffic is not used to train their models. Each workspace's agent sees only that workspace's data, spends only within the autonomy and credit limits you set, and every action it takes is logged in your activity trail.

๐Ÿงพ Subprocessors

ProviderPurpose
SupabaseManaged PostgreSQL database, backups
StripePayments & billing (PCI-DSS Level 1)
Anthropic & GoogleAI models (no training on API data)
ResendTransactional email delivery
Specialist data providersContact, signal & phone verification โ€” vetted for GDPR posture; full list available on request

๐Ÿ›ก๏ธ Operational practices

Least-privilege access, separated environments, secrets kept out of source control, automated dependency and error monitoring with on-call alerting, rate limiting on all public endpoints, and full audit logging of agent actions inside each workspace.

๐Ÿข On the enterprise roadmap

SAML/OIDC single sign-on, role-based access control, and a SOC 2 audit are on our enterprise roadmap โ€” we pursue certifications as our enterprise footprint grows, and we'd rather tell you that honestly than rent a badge. If your security team has a questionnaire, we'll answer it directly: security@bosr.ai.

๐Ÿ› Responsible disclosure

Found a vulnerability? Email security@bosr.ai. We respond within 48 hours, fix confirmed issues fast, and credit researchers who report in good faith. Please don't test against other customers' data.