Trust

Security at BosAI

Updated July 21, 2026

Security is the product at BosAI: the Service acts inside your business accounts, so protecting them is our first job. This page summarizes our practices in plain language. Contractual security commitments for business customers are in the Data Processing Addendum (Annex II).

1. Architecture and Access

Connections to your tools (QuickBooks, Stripe, Square, Gmail, Google Calendar) use each provider's authorized interfaces and OAuth authorization. We request only the permission scopes a feature needs, you approve them explicitly, and you can revoke them at any time from BosAI or from the provider. We do not ask for, and do not store, the passwords to your connected accounts. BosAI never holds or moves your money.

2. Encryption

All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Secrets and connection tokens are stored in a dedicated secrets-management system with access logging and rotation.

3. Least Privilege Inside BosAI

Customer data access by our personnel is restricted to a need-to-know basis, gated by single sign-on with multi-factor authentication, granted per role, logged, and reviewed. Human access to Customer Content is limited to what is described in our Privacy Policy (for example, debugging an issue with your consent).

4. The Receipt System

Every material action an AI Employee takes is logged with what happened, when, on whose authorization, and through which connection. Receipts are visible to you in the product and exportable. This is both a trust feature and a security control: unexpected activity is visible immediately.

5. Development and Testing

Code changes go through review and automated testing before release. Dependencies are scanned for known vulnerabilities. We conduct periodic penetration testing through independent firms [cadence and current attestation status available on request] and operate continuous monitoring and alerting in production.

6. Resilience

The Service runs on enterprise cloud infrastructure with physical security, redundancy, and availability zones managed by the infrastructure provider. Data is backed up in encrypted form, and restoration procedures are tested periodically.

7. Incident Response

We maintain a documented incident response plan with severity levels, on-call escalation, and customer notification procedures. If an incident affects your personal data, we will notify you as required by law, and for business customers under the DPA, without undue delay and within 72 hours of our becoming aware.

8. Responsible Disclosure

We welcome good-faith security research. If you believe you have found a vulnerability, email info@file.business (Subject: Security) with details and steps to reproduce. Please do not access other customers' data, degrade the Service, or publicly disclose before we have had a reasonable opportunity to remediate. We will acknowledge reports promptly and keep you informed; we do not pursue legal action against good-faith research that respects these guidelines.

Security questions: info@file.business (Subject: Security).