How Boatwork Assist protects customer data, scopes agent access, and governs multi-tenant AI operations — written plainly for the people who have to sign off on it.
Controls
These are the controls the platform runs on today — described plainly, so the people who have to sign off know exactly what they're getting.
FAQ
Yes. Each organization runs in its own logically isolated tenant. Agents operate only within the org they're deployed to.
No. An agent only accesses the specific inboxes and connectors you connect and assign to it.
All data is encrypted in transit with TLS, every org runs in its own isolated tenant, and agents act only through scoped, revocable tokens. Encryption at rest is on our roadmap as the platform matures.
No. We do not train foundation models on your organization data. Your Org Context CDN serves your own agents only.
From the console you can disconnect any connector or pause an agent at any time. Revocation takes effect immediately.
We're on a deliberate path toward formal certification, starting with SOC 2 and adding HIPAA and PCI where customers need them. The platform already runs on the controls those frameworks are built on — tenant isolation, least-privilege access, immediate revocation, and audit logging.