Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how Boundera Inc. ("Boundera", "we") handles information across our marketing website and the Boundera platform.
The short version: website analytics run only with your consent, Boundera Cloud data is used only to provide the service, and self-hosted deployments keep your data in your own environment.
What This Policy Covers
This policy covers:
- The marketing website at boundera.io
- Boundera Cloud, the hosted version of the Boundera platform
- Self-hosted deployments, where the policy explains what little we receive (see the self-hosted section below)
If your organization has a signed agreement with Boundera that addresses data handling, that agreement governs where it conflicts with this policy.
Information We Collect on the Website
The marketing website may use analytics tools and advertising platform tags to understand site usage, measure campaign performance, and build remarketing audiences:
- Analytics events such as page views, CTA clicks, and demo requests
- Attribution data such as UTM parameters and referring campaign metadata
- Advertising tags from platforms such as Meta and Google, when enabled
- Contact details you choose to give us, such as your name and work email when you request a demo or contact us
Analytics and advertising technologies are used only on the marketing site and are not required to browse it. You can accept or decline them through the site's cookie banner.
Information We Collect in Boundera Cloud
When your organization uses Boundera Cloud, we process:
- Account information: names, work email addresses, and roles of the users your organization adds
- Customer data: data your organization submits to the platform, such as cloud configuration metadata, security findings, evidence artifacts, and compliance documents
- Connector credentials: credentials for the integrations you configure, such as cloud providers, identity providers, and ticketing systems. They are stored encrypted and used only to run those integrations.
- Usage data: technical logs about how the platform operates, excluding customer data
We use customer data only to provide, maintain, secure, and support the platform for your organization. We do not use it for advertising, retargeting, or unrelated marketing analytics. Usage data is not shared externally unless it is de-identified and aggregated.
Self-Hosted Deployments
Self-hosted Boundera, for example installed from AWS Marketplace, runs inside your own cloud account. It is designed so that:
- Your configuration data, findings, and evidence stay in your environment. Boundera does not receive them.
- Boundera has no access to your cloud account, your databases, or your storage.
- Integration credentials you configure are stored encrypted in your own deployment's database, not with Boundera.
- We hold only the business records needed to manage your purchase, license, and support requests, plus whatever you choose to share with us when you ask for help.
Purchases through AWS Marketplace are processed by AWS. AWS shares limited subscription information with us, as described in the AWS Marketplace terms.
AI Features
Some optional platform features, such as remediation suggestions and policy drafting, use large language models. Core validation is rule-based and makes no AI calls.
- In Boundera Cloud, prompts are processed by third-party AI model providers acting on our behalf.
- In self-hosted deployments, prompts go directly from your environment to the AI provider you configure, such as Amazon Bedrock in your own AWS account or model provider API keys you supply. Boundera never receives them.
- You may disable the AI features at any time.
- Boundera will not use your data to train or improve any AI model.
How We Share Information
We do not sell or rent your information. We share it only with:
- Service providers that help us run the Service, such as cloud infrastructure providers, under agreements that protect your data
- Third-party AI model providers, only for the optional AI features described above
- Analytics and advertising platforms, only for marketing-site data and only with your cookie consent
- Authorities, when the law requires it; where permitted, we will give you reasonable advance notice
Data Retention and Deletion
- Your organization can export its data from Boundera Cloud during its subscription.
- After a subscription ends, we delete customer data within 60 days of your request, except for backups kept under our standard retention practices or as required by law.
- Website and marketing data is kept only as long as needed for the purposes described in this policy.
Security
We protect data with industry-standard technical and organizational measures, including encryption in transit and at rest, least-privilege access, and logging. No system is perfectly secure, so we also limit what we collect to what the Service needs.
Your Rights and Choices
You can ask us to access, correct, or delete the personal information we hold about you by writing to legal@boundera.io. We respond to requests as required by applicable law.
If your personal information is in a customer's Boundera Cloud account, we process it on that customer's behalf. Contact that organization first, and we will support their response.
Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to This Policy
This Privacy Policy may be updated from time to time. Updates will be reflected on this page with a revised "Last updated" date.
Contact
Boundera Inc., 160 W Camino Real, Suite #996, Boca Raton, FL 33432. Privacy questions: legal@boundera.io.