Security & Privacy
Security by design. Defined for your business.
Responsible implementation starts with clear boundaries around your information,
your people, and your systems.
The specific architecture, controls, and subprocessors are documented during implementation and may vary by customer.
Customer Data Ownership
Customers retain ownership of their business information. Ownership and permitted processing are documented as part of the customer agreement.
Data Isolation
Customer information is logically separated from other client environments, with access limited by authenticated user permissions. The isolation approach is defined and validated for the specific implementation.
Access Controls
Production deployments use individual authentication and role-based access controls where appropriate. Access is configured around the responsibilities and approved audiences for the system.
Encryption
Infrastructure providers are selected to support encryption of information in transit and at rest. The services and settings used for each deployment are reviewed during implementation.
AI Data Use
When supported AI business or API services are used, customer business information is processed under the provider’s business-data terms and is not used to train public foundation models by default. The applicable service, terms, settings, and any exceptions are reviewed for each implementation. For example, OpenAI’s business-data terms describe its default approach for business products and the API.
Least-Privilege Access
BossCo systems and integrations should receive only the permissions necessary to perform the approved business function. Required access is identified during setup and reviewed when the scope changes.
Approved Knowledge
Knowledge systems can distinguish between information intended for employees, dealers, customers, or other audiences. Source approval and access boundaries are established before information is made available.
Monitoring and Logging
Production systems can maintain appropriate activity and diagnostic logs while avoiding unnecessary storage of credentials and sensitive information. The scope of logging and access to logs are defined for the deployment.
Data Retention
Customer data retention and deletion requirements can be established as part of deployment. The implementation documents applicable storage locations, provider limitations, and the process for requesting deletion.
Infrastructure
BossCo may use established infrastructure and AI providers such as Vercel, Supabase, OpenAI, and other approved third-party platforms depending on the implementation. Specific architecture and subprocessors may vary by customer and are documented during implementation.
This Website & Your Privacy
This website does not use advertising trackers, analytics, or a contact-delivery service. Enquiry details remain in your current browser page until you navigate away or close it. A downloaded enquiry is saved on your own device. Opening an email draft passes the details to your chosen email app; that app’s privacy terms apply. You decide whether to send it.
Vercel hosts this website and may process routine technical request information. If you send an enquiry by email, BossCo receives the contact details and message you choose to send. For questions about that information, contact basoce7@gmail.com.
This page describes our implementation approach. It is not a certification statement or a substitute for the controls and terms agreed for a specific customer deployment.