Security & Privacy

Security by design. Defined for your business.

Responsible implementation starts with clear boundaries around your information,
your people, and your systems.

The specific architecture, controls, and subprocessors are documented during implementation and may vary by customer.

Customer Data Ownership

Customers retain ownership of their business information. Ownership and permitted processing are documented as part of the customer agreement.

Data Isolation

Customer information is logically separated from other client environments, with access limited by authenticated user permissions. The isolation approach is defined and validated for the specific implementation.

Access Controls

Production deployments use individual authentication and role-based access controls where appropriate. Access is configured around the responsibilities and approved audiences for the system.

Encryption

Infrastructure providers are selected to support encryption of information in transit and at rest. The services and settings used for each deployment are reviewed during implementation.

AI Data Use

When supported AI business or API services are used, customer business information is processed under the provider’s business-data terms and is not used to train public foundation models by default. The applicable service, terms, settings, and any exceptions are reviewed for each implementation. For example, OpenAI’s business-data terms describe its default approach for business products and the API.

Least-Privilege Access

BossCo systems and integrations should receive only the permissions necessary to perform the approved business function. Required access is identified during setup and reviewed when the scope changes.

Approved Knowledge

Knowledge systems can distinguish between information intended for employees, dealers, customers, or other audiences. Source approval and access boundaries are established before information is made available.

Monitoring and Logging

Production systems can maintain appropriate activity and diagnostic logs while avoiding unnecessary storage of credentials and sensitive information. The scope of logging and access to logs are defined for the deployment.

Data Retention

Customer data retention and deletion requirements can be established as part of deployment. The implementation documents applicable storage locations, provider limitations, and the process for requesting deletion.

Infrastructure

BossCo may use established infrastructure and AI providers such as Vercel, Supabase, OpenAI, and other approved third-party platforms depending on the implementation. Specific architecture and subprocessors may vary by customer and are documented during implementation.

This Website & Your Privacy

This website does not use advertising trackers, analytics, or a contact-delivery service. Enquiry details remain in your current browser page until you navigate away or close it. A downloaded enquiry is saved on your own device. Opening an email draft passes the details to your chosen email app; that app’s privacy terms apply. You decide whether to send it.

Vercel hosts this website and may process routine technical request information. If you send an enquiry by email, BossCo receives the contact details and message you choose to send. For questions about that information, contact basoce7@gmail.com.

This page describes our implementation approach. It is not a certification statement or a substitute for the controls and terms agreed for a specific customer deployment.

A useful place to start.

Talk With Us