๐ No passwords to steal
Sign-in is magic-link only โ we never store a password, so there is no password database to breach, phish, or reuse. Sessions use short-lived tokens with rotating refresh credentials. Channel connections (Gmail, Microsoft, LinkedIn, WhatsApp, calendars) use OAuth or hosted authentication: your credentials are never typed into, seen by, or stored on BOSRAI. Revoke any connection with one click, any time.
๐ Encryption, both directions
All traffic is TLS-encrypted in transit. At rest, your data lives in a managed PostgreSQL cluster (Supabase) with AES-256 encryption, continuous backups, and point-in-time recovery. Payments are processed entirely by Stripe โ card numbers never touch our servers, ever.
๐ช๐บ Visitor tracking that respects visitors
Our website-visitor lead feature was designed EU-safe from day one, because most tools in this category weren't: the snippet is cookieless, sets no identifiers in the browser, resolves companies only (never people), and raw IP addresses are never persisted โ only a salted one-way hash for deduplication. Home and mobile ISP traffic is deliberately discarded.
๐ฆ Your data is yours
Export your contacts, deals, and conversations at any time. When you delete your workspace, your data is deleted โ not archived into a "legitimate interest" black hole. We don't sell data, we don't train shared models on your pipeline, and your business knowledge (ICP, messaging, objection learnings) stays inside your workspace.
๐ค AI, scoped tightly
AI features run against leading model providers (Anthropic, Google) under their enterprise API terms โ API traffic is not used to train their models. Each workspace's agent sees only that workspace's data, spends only within the autonomy and credit limits you set, and every action it takes is logged in your activity trail.
๐งพ Subprocessors
| Provider | Purpose |
|---|---|
| Supabase | Managed PostgreSQL database, backups |
| Stripe | Payments & billing (PCI-DSS Level 1) |
| Anthropic & Google | AI models (no training on API data) |
| Resend | Transactional email delivery |
| Specialist data providers | Contact, signal & phone verification โ vetted for GDPR posture; full list available on request |
๐ก๏ธ Operational practices
Least-privilege access, separated environments, secrets kept out of source control, automated dependency and error monitoring with on-call alerting, rate limiting on all public endpoints, and full audit logging of agent actions inside each workspace.
๐ข On the enterprise roadmap
SAML/OIDC single sign-on, role-based access control, and a SOC 2 audit are on our enterprise roadmap โ we pursue certifications as our enterprise footprint grows, and we'd rather tell you that honestly than rent a badge. If your security team has a questionnaire, we'll answer it directly: security@bosr.ai.
๐ Responsible disclosure
Found a vulnerability? Email security@bosr.ai. We respond within 48 hours, fix confirmed issues fast, and credit researchers who report in good faith. Please don't test against other customers' data.