Security and Trust
How your data is handled
What is collected, who can access it, where it is stored, and how long it is kept. Each answer below points to the section of the iboss policy that governs it.
Data handling for AI Security Platform is governed by the iboss Terms of Use, Privacy Policy, and Data Processing Addendum. That document governs. The summaries below exist to point you at the section that answers each question.
What is collected
The iboss Privacy Policy defines Platform Personal Information as including email addresses, IP addresses, login credentials, website search terms, websites visited, and files downloaded.
What is actually collected for your organization depends on the policies your administrators enable. Conversation monitoring, for example, is a per-policy setting, so you decide which AI services have prompts and responses captured.
Source: Privacy Policy: What Information Do We Collect And From What Sources?
Who can access it
The policy states that iboss does not ordinarily access or review Platform Personal Information, because it is protected within segregated, containerized reporting databases that isolate it. It further states that critical information such as passwords is subject to security measures designed to prevent direct access by iboss.
By default the data is accessible only to you and to the administrators and other authorized users you designate. The policy notes that a customer may separately grant iboss administrative access, typically in order to receive support.
Source: Privacy Policy: What Information Do We Collect And From What Sources?
How it is processed
Processing purposes are set out in the Privacy Policy. Where iboss processes Customer Personal Data subject to the GDPR on your behalf, the iboss Data Processing Addendum is incorporated into the Terms by reference and applies.
Source: Privacy Policy: How Do We Use Personal Information? and the Data Processing Addendum
Where it is stored
Data is processed in the global data center closest to the end user's physical location. The policy states that the customer can designate and control where processed data is stored, based on its own geo-location requirements.
That means an EU-based customer can require that data from all of its end users, wherever those users are located, be processed and stored only in EU-based data centers. iboss stores information about prospective and actual customers primarily in the United States and also in the United Kingdom, and relies on EU Standard Contractual Clauses for transfers to countries without an adequacy determination.
Source: Privacy Policy: Do We Transfer Personal Information Internationally?
How long it is retained
iboss retains Personal Information as long as reasonably necessary for the business purposes described in the Privacy Policy, as long as reasonably necessary to provide the platform, or as reasonably necessary to comply with legal obligations, resolve disputes, and enforce agreements.
The policy sets out the criteria used to determine an appropriate retention period: the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for processing and whether they can be achieved another way, and applicable legal requirements.
The published policy is a standard rather than a fixed period, and names no specific number of days. We do not quote one here for that reason. Separately, how far back you can look at activity inside the product varies by plan tier, which is shown on the pricing page.
Source: Privacy Policy: What Is Our Personal Information Retention Policy?
Safeguards
iboss uses technical and physical safeguards to protect Personal Information from unauthorized disclosure, and makes commercially reasonable efforts to ensure that only necessary people and third parties have access to it.
That section is expressly qualified, noting that such measures cannot prevent all loss, misuse, or alteration. Read it in full rather than relying on this summary.
Source: Privacy Policy: How Does iboss Secure Your Personal Information?
Compliance
Certifications and authorizations held by iboss, Inc., as published by iboss. These describe the company's compliance posture rather than the scope of any individual feature of this product.
- FedRAMP Authorized
- StateRAMP Authorized
- FIPS 140-2
- HIPAA
- CJIS
- FERPA
- SOC 2 Type II
- GDPR
- CMMC 2.0 Ready
Questions about privacy or data handling
Privacy questions go to privacy@iboss.com. iboss has also appointed an EU representative, named in the Privacy Policy. For questions about your specific environment, talk to sales.