Security Measures at Bounded

Last updated: August 17, 2026

Security is integral to the way Bounded is designed, built, and operated. This page describes the measures we maintain to protect customer data and to ensure confidentiality, integrity, and availability across the service.

Service overview

Bounded is delivered as a cloud-hosted service accessible via web and desktop clients. Customer documents and permanent platform data are stored on Bounded-operated Hetzner infrastructure in the EU. External processing steps, including limited AI processing, are restricted to necessary, preprocessed, and minimized extracts and are disclosed through our sub-processor information. Production administration is restricted, logged, and available only through private network paths.

Governance and management

Bounded operates an Information Security Management System aligned with ISO/IEC 27001:2022 and is undergoing external certification. We have completed the Stage 1 audit and have been recommended to proceed to Stage 2. Our Stage 2 audit is scheduled for September 2026; Bounded is not certified until the external certification process is complete. Responsibilities for security are assigned and documented. Policies cover access control, asset management, change management, incident response, vendor risk, and business continuity. Risks and security measures are reviewed with documented outcomes. Security responsibilities, incident reporting, and rules for sensitive information are documented for the current founder team and will be formalized further as the team grows.

Data protection

We collect only the data required to provide the service. Data is protected in transit using modern TLS. Sensitive customer documents are encrypted with AES-256-GCM, with a unique key for each document. Encryption keys are isolated from encrypted data in a dedicated OpenBao key vault on a separate EU instance. Administrative access to OpenBao uses federated authentication; applications use short-lived tokens, and key-vault operations are audit logged. Original files are not sent to AI models. Only necessary, preprocessed, and minimized text extracts are used for AI analysis. Retention schedules are documented, and data is deleted securely when no longer required.

Access management

Customer authentication supports Single Sign-On and multi-factor authentication through Zitadel. Within Bounded, role-based controls enforce least privilege at organization level. Administrative access to the Bounded application uses a separate federated login and multi-factor authentication. Infrastructure access is available only through Bounded's private VPN using Secure Enclave-protected SSH keys. OpenBao administration uses federated authentication, while application access uses short-lived tokens. Administrative and key-vault activity is logged. Company devices used to access production resources are protected with full-disk encryption, endpoint protection, and screen-lock policies.

Infrastructure and network security

The production environment is segregated from development and testing. Network boundaries are enforced using private networks, segmented service networks, and firewall rules that restrict management and service traffic. Internal administration and observability services are available only through the private VPN. Systems are updated according to risk, and logs, traces, and metrics are collected centrally to support detection and investigation. Access to the management plane is restricted and logged.

Application security

Software changes follow a secure development lifecycle. Code is reviewed, tests are run for relevant changes, and executable checks enforce security-relevant coding conventions. Dependencies are reviewed on a defined cadence and when material risks are identified. Secrets are not stored in source code; they are held in OpenBao with least-privilege access and documented rotation procedures.

Monitoring, vulnerability, and change management

Bounded centralizes application and infrastructure telemetry and maintains alerts for critical, actionable events. Vulnerabilities in code, dependencies, and infrastructure are reviewed on a defined cadence and when material changes or findings occur. Findings are prioritized by impact and likelihood. Critical issues are addressed promptly, and lower-risk items are scheduled according to risk. Changes to production follow a documented process with testing, review, and controlled deployment.

Incident response

A documented incident response plan covers detection, triage, containment, eradication, and recovery. Central monitoring and configured alerts support detection and escalation. If customer data is affected, Bounded will notify the affected customer without undue delay and provide relevant details, remediation steps under way, and any recommended customer actions. After resolution, a post-incident review identifies lessons and relevant corrective actions.

Business continuity and disaster recovery

Backups are encrypted and taken on a defined cadence. Restoration procedures are documented and included in Bounded's quarterly verification plan. Recovery targets are established per critical component based on customer needs, data classification, and demonstrated restoration capability.

Sub‑processors

Bounded uses a limited number of specialist providers. We maintain a supplier register and review providers based on criticality, the data processed, jurisdiction, and material service changes. The list is available upon request. Material changes are communicated in accordance with our customer commitments.

Shared responsibility

Security in the cloud is shared. Bounded provides the platform, controls, and guidance. Customers are responsible for tenant configuration, user lifecycle management, and enforcement of their own access policies, including the use of SSO and MFA. Configuration guidance and best practices are available upon request.

Contact

For security or compliance inquiries, contact security@boundedsystems.com.