BoatworkSecurity
Boatwork Assist / Security & data governance

Security and data governance

How Boatwork Assist protects customer data, scopes agent access, and governs multi-tenant AI operations — written plainly for the people who have to sign off on it.

Request a security reviewSee the controls

Controls

The controls underneath the platform.

These are the controls the platform runs on today — described plainly, so the people who have to sign off know exactly what they're getting.

Tenant isolation

Logically isolated tenantsOrg Context CDN scoped to your tenantNo cross-tenant queries

Role-based access

Roles limit who manages agentsLeast-privilege connector scopesOwner approval for sensitive changes

Credentials & transit encryption

Data encrypted in transit (TLS)Encryption at rest on the roadmapAgents act through scoped tokens

OAuth & revocation

Disconnect connectors from the consoleRevocation takes effect immediatelyNo access beyond what you grant

Agent capability controls

Confirm-gating for sensitive actionsPer-agent scopesPause or retire an agent anytime

Audit logs & retention

Action and access logsReview & incident-response supportData export on request

FAQ

What security teams ask before they sign off.

On a deliberate path to certification.
SOC 2HIPAAPCI

Is it multi-tenant?

Yes. Each organization runs in its own logically isolated tenant. Agents operate only within the org they're deployed to.

Can agents access all company mailboxes?

No. An agent only accesses the specific inboxes and connectors you connect and assign to it.

Is data encrypted?

All data is encrypted in transit with TLS, every org runs in its own isolated tenant, and agents act only through scoped, revocable tokens. Encryption at rest is on our roadmap as the platform matures.

Do you train models on our data?

No. We do not train foundation models on your organization data. Your Org Context CDN serves your own agents only.

How do we revoke access?

From the console you can disconnect any connector or pause an agent at any time. Revocation takes effect immediately.

What certifications do you have?

We're on a deliberate path toward formal certification, starting with SOC 2 and adding HIPAA and PCI where customers need them. The platform already runs on the controls those frameworks are built on — tenant isolation, least-privilege access, immediate revocation, and audit logging.

Need a security review?

We can provide scope details, answer vendor questionnaires, and walk your team through your connector setup.

Request a security reviewBack to Boatwork Assist