Skip to main content

Start your 7-day free trial today. Get Started →

Security built for confidential patent work.

Your work runs on enterprise AI model endpoints, not consumer AI. It is never used to train a model and is encrypted in transit and at rest.

Certifications and assurance

Independently audited and continuously monitored, with the evidence available to your security team under NDA.

SOC 2 Type 2 attested

Our controls are tested as operating effectively over a multi-month period, not just designed at a point in time. The attestation covers the AICPA Trust Services Criteria, including access controls, system operations, and incident response.

ISO 27001 certified

Accredited third-party certification of our Information Security Management System, maintained by annual surveillance audits and built on continual improvement.

Independent penetration testing

Application and network penetration tests are performed by a third party against OWASP methodology. Findings are remediated to severity-based timelines and verified by retest.

Continuous monitoring and audit logging

Vulnerability scanning, threat detection, and complete audit logging of user actions run continuously rather than as a one-time check. Live service status is published at status.boundly.ai.

The SOC 2 Type 2 report, ISO 27001 certificate, penetration-test summary, and DPA are available to evaluators under NDA via the Trust Center.

Security FAQ

Do you train AI models on my data?
No. Your prompts, documents, and generated content are never used to train any model, including third-party models we route to. This is enforced at the contract level with every model provider and documented in your DPA.
Where is my data stored?
Storage and processing details depend on your deployment and setup. If you need region-specific or infrastructure-specific details, contact us and we can walk you through them directly.
Can Boundly employees see my data?
Access to customer data is strictly controlled and limited to authorized personnel for support purposes only, with full audit logging.
How do I request data deletion?
Contact us at [email protected]. We process deletion requests within 30 days.
Which subprocessors does Boundly use?
We maintain a current list of subprocessors (cloud infrastructure and the model providers we route to) in our Trust Center, available on request. Every subprocessor is bound by no-training and data-handling terms at the contract level, and we notify customers of material changes before they take effect.
Does a human ever read my prompts or documents?
Boundly does not read your matters to review, improve, or train anything, and staff access to customer data is limited to authorized personnel for support purposes only, with full audit logging. The enterprise model providers we route to are bound by no-training and data-handling terms at the contract level, and your work is never used to train or improve any model.
How can I get your SOC 2 report and security documentation?
Boundly holds an active SOC 2 Type 2 attestation and is ISO 27001 certified. Both reports, along with our DPA and subprocessor list, are available under NDA through our Trust Center. Contact us at [email protected] to request access.