Skip to main content
Pricing
Sign inGet started

Security at Boundera

Last updated: August 13, 2026

We build software that measures security posture, so ours has to hold up first. This page describes how we secure the Boundera platform and how to reach us about security.

We Run Boundera on Boundera

Boundera uses its own production platform internally while pursuing FedRAMP 20x Class C certification. Our Key Security Indicator results are published on our own live Trust Center, produced by the same continuous validation engine our customers use.

  • The Boundera platform passed the AWS Foundational Technical Review in July 2026.
  • Our Secure Configuration Guide is public, so you can see exactly how we expect a hardened deployment to look.

Platform Security

  • Boundera Cloud runs on Amazon Web Services in U.S. regions.
  • Data is encrypted in transit with TLS and encrypted at rest.
  • Connector credentials are additionally encrypted at the application layer before they are stored.
  • Customer environments are logically isolated. Access follows a role-based model, scoped per organization and per customer.
  • Multi-factor authentication is supported for platform sign-in.

Self-Hosted Deployments

Boundera is also available self-hosted, for example through AWS Marketplace. In that model:

  • The software runs entirely inside your cloud account. Your evidence, findings, and configuration data never leave your boundary.
  • Boundera has no access to your environment.
  • Optional AI features run against your own model access, such as Amazon Bedrock in your own AWS account, so prompts never leave your control either.

Connector Least Privilege

  • Connectors read security and configuration metadata. They are designed for least-privilege, read-only access wherever the provider supports it, and our documentation publishes the exact permissions each connector needs.
  • You can revoke a connector's access at any time from your cloud or identity provider.
  • Credentials are stored encrypted and used only to run the integrations you configure.

AI Security and Data Use

  • Core KSI validation is rule-based. AI never decides your compliance status.
  • Optional AI features (remediation suggestions and policy drafting) can be disabled at any time.
  • Boundera does not use customer data to train or improve any AI model.
  • Agentic fixes are proposals. A human approves before anything ships.

Secure Development

Changes to the platform go through peer-reviewed pull requests and automated test suites before release, and deploy through staged environments. The same validation engine we sell runs against our own production boundary continuously.

Incident Response

If we confirm a security incident in Boundera's own systems that affects our customers, we notify affected customers' security contacts within 24 hours of confirmation and keep them informed through resolution.

Vulnerability Disclosure

We welcome good-faith security research. Report vulnerabilities to security@boundera.io (also listed in our security.txt). We acknowledge reports promptly and will keep you informed as we investigate.

  • Do not run automated scanning or disruptive testing against Boundera Cloud without our written approval.
  • Self-hosted installations run in your own environment, so you are free to security-test your own deployment.
  • We will not pursue legal action against research conducted in good faith that respects user privacy and this policy.

Insurance

Boundera maintains US$5,000,000 in Cyber and Technology Errors & Omissions coverage. A certificate of insurance is available on request.

Subprocessors

Boundera Cloud uses a small set of subprocessors:

  • Amazon Web Services: cloud infrastructure and hosting
  • Email delivery providers: transactional email
  • Website analytics and advertising platforms: marketing site only, with cookie consent
  • AI model providers: optional AI features only, as described in our Privacy Policy

The current list is available from legal@boundera.io. Self-hosted deployments introduce no Boundera subprocessors; your data stays with you.

Data Retention and Deletion

You can export your data from Boundera Cloud during your subscription. After a subscription ends, we delete customer data within 60 days of your request, except for backups kept under our standard retention practices or as required by law. Details are in our Terms of Service and Privacy Policy.

Contact

Security questions and reports: security@boundera.io. Legal and privacy: legal@boundera.io.