Skip to main content
Pricing
Sign inGet started

Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how Boundera Inc. ("Boundera", "we") handles information across our marketing website and the Boundera platform.

The short version: website analytics run only with your consent, Boundera Cloud data is used only to provide the service, and self-hosted deployments keep your data in your own environment.

What This Policy Covers

This policy covers:

  • The marketing website at boundera.io
  • Boundera Cloud, the hosted version of the Boundera platform
  • Self-hosted deployments, where the policy explains what little we receive (see the self-hosted section below)

If your organization has a signed agreement with Boundera that addresses data handling, that agreement governs where it conflicts with this policy.

Information We Collect on the Website

The marketing website may use analytics tools and advertising platform tags to understand site usage, measure campaign performance, and build remarketing audiences:

  • Analytics events such as page views, CTA clicks, and demo requests
  • Attribution data such as UTM parameters and referring campaign metadata
  • Advertising tags from platforms such as Meta and Google, when enabled
  • Contact details you choose to give us, such as your name and work email when you request a demo or contact us

Analytics and advertising technologies are used only on the marketing site and are not required to browse it. You can accept or decline them through the site's cookie banner.

Information We Collect in Boundera Cloud

When your organization uses Boundera Cloud, we process:

  • Account information: names, work email addresses, and roles of the users your organization adds
  • Customer data: data your organization submits to the platform, such as cloud configuration metadata, security findings, evidence artifacts, and compliance documents
  • Connector credentials: credentials for the integrations you configure, such as cloud providers, identity providers, and ticketing systems. They are stored encrypted and used only to run those integrations.
  • Usage data: technical logs about how the platform operates, excluding customer data

We use customer data only to provide, maintain, secure, and support the platform for your organization. We do not use it for advertising, retargeting, or unrelated marketing analytics. Usage data is not shared externally unless it is de-identified and aggregated.

Self-Hosted Deployments

Self-hosted Boundera, for example installed from AWS Marketplace, runs inside your own cloud account. It is designed so that:

  • Your configuration data, findings, and evidence stay in your environment. Boundera does not receive them.
  • Boundera has no access to your cloud account, your databases, or your storage.
  • Integration credentials you configure are stored encrypted in your own deployment's database, not with Boundera.
  • We hold only the business records needed to manage your purchase, license, and support requests, plus whatever you choose to share with us when you ask for help.

Purchases through AWS Marketplace are processed by AWS. AWS shares limited subscription information with us, as described in the AWS Marketplace terms.

AI Features

Some optional platform features, such as remediation suggestions and policy drafting, use large language models. Core validation is rule-based and makes no AI calls.

  • In Boundera Cloud, prompts are processed by third-party AI model providers acting on our behalf.
  • In self-hosted deployments, prompts go directly from your environment to the AI provider you configure, such as Amazon Bedrock in your own AWS account or model provider API keys you supply. Boundera never receives them.
  • You may disable the AI features at any time.
  • Boundera will not use your data to train or improve any AI model.

How We Share Information

We do not sell or rent your information. We share it only with:

  • Service providers that help us run the Service, such as cloud infrastructure providers, under agreements that protect your data
  • Third-party AI model providers, only for the optional AI features described above
  • Analytics and advertising platforms, only for marketing-site data and only with your cookie consent
  • Authorities, when the law requires it; where permitted, we will give you reasonable advance notice

Data Retention and Deletion

  • Your organization can export its data from Boundera Cloud during its subscription.
  • After a subscription ends, we delete customer data within 60 days of your request, except for backups kept under our standard retention practices or as required by law.
  • Website and marketing data is kept only as long as needed for the purposes described in this policy.

Security

We protect data with industry-standard technical and organizational measures, including encryption in transit and at rest, least-privilege access, and logging. No system is perfectly secure, so we also limit what we collect to what the Service needs.

Your Rights and Choices

You can ask us to access, correct, or delete the personal information we hold about you by writing to legal@boundera.io. We respond to requests as required by applicable law.

If your personal information is in a customer's Boundera Cloud account, we process it on that customer's behalf. Contact that organization first, and we will support their response.

Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes to This Policy

This Privacy Policy may be updated from time to time. Updates will be reflected on this page with a revised "Last updated" date.

Contact

Boundera Inc., 160 W Camino Real, Suite #996, Boca Raton, FL 33432. Privacy questions: legal@boundera.io.