Protected while moving and while stored.
The browser calls the regional API directly.
The control plane authorises a short-lived project session. The browser then calls the regional API without a content-proxy fallback.
Projects are fixed to one region.
A project has one permanent region, and project credentials cannot cross project or region boundaries.
Controls built into the product.
Short-lived dashboard sessions
The control plane issues signed, short-lived regional tokens. Communication content is read directly from the selected region, not copied into a global dashboard database.
Fail-closed regional reads
If a regional session is missing, expired, or unauthorised, the dashboard does not fall back to a control-plane content proxy.
What we are still proving.
Security is an operating practice, not a finished feature. These items remain visible until their implementation and production evidence are complete.
- Customer-configurable retention and scheduled deletion are not implemented or enforced.
- Backup retention, restore testing, support-access evidence, and the complete observability path are not yet published as verified regional guarantees.
- A formal penetration-test summary and independent security certification are not currently available.
- Service-level commitments are contractual only when included in a signed order. The public service has no published uptime SLA.
Report a security issue.
Please send suspected vulnerabilities or security incidents to security@boundry.dev. Do not include live credentials, message bodies, or personal information in the first report. We will provide a secure path if evidence is required.