Security built for confidential patent work.
Your work runs on enterprise AI model endpoints, not consumer AI. It is never used to train a model and is encrypted in transit and at rest.
The guarantees
Plain language commitments for teams handling privileged and confidential invention disclosures.
Enterprise model endpoints
Your work runs on enterprise AI model endpoints, not the public consumer apps. Every model provider is bound by no-training and data-handling terms at the contract level, and your matters stay scoped to your organization.
No training on your data
Prompts, documents, and outputs are never used to train or improve any foundation model, and are never shared with the underlying model providers.
Encrypted in transit and at rest
All data is encrypted with TLS 1.3 in transit and AES-256 at rest, with keys managed under our SOC 2 Type 2 and ISO 27001 controls.
Your data stays yours
Customer data is retained only as needed to deliver the service. It is exportable and can be deleted on request, with documented retention and deletion practices.
Role-based access and MFA
Least-privilege role-based access, multi-factor authentication, SSO support, and segregation of duties. Privileged access to production is restricted, logged, and reviewed.
Incident response
A formal, tested incident-response process is maintained under our SOC 2 Type 2 and ISO 27001 controls. Incident response and breach notification terms are covered in our DPA.
Certifications and assurance
Independently audited and continuously monitored, with the evidence available to your security team under NDA.
SOC 2 Type 2 attested
Our controls are tested as operating effectively over a multi-month period, not just designed at a point in time. The attestation covers the AICPA Trust Services Criteria, including access controls, system operations, and incident response.
ISO 27001 certified
Accredited third-party certification of our Information Security Management System, maintained by annual surveillance audits and built on continual improvement.
Independent penetration testing
Application and network penetration tests are performed by a third party against OWASP methodology. Findings are remediated to severity-based timelines and verified by retest.
Continuous monitoring and audit logging
Vulnerability scanning, threat detection, and complete audit logging of user actions run continuously rather than as a one-time check. Live service status is published at status.boundly.ai.
The SOC 2 Type 2 report, ISO 27001 certificate, penetration-test summary, and DPA are available to evaluators under NDA via the Trust Center.
Simple pricing. No surprises.
Choose monthly or yearly billing. Full access to all tools on every plan.

