Purchase invoice · PI-2026-0412
₱248,400.00
Over the approval threshold for this cost centre
This page separates three things: controls enforced in our own code, controls our platform providers operate, and things that are simply not in place yet. Mixing those together is how security pages mislead people.
It previously described a certification readiness assessment, a scheduled external penetration test, specific encryption versions and a response-time commitment. None of those could be evidenced, so they have been removed rather than reworded. We would rather publish less and have all of it be true.
Approvals are enforced where the data lives, not by hiding a button. Every one names the person who gave it and the moment they did, and a posted record cannot be quietly edited afterwards — a correction is a new entry that leaves both visible.
Each of these is implemented in the application and the database rather than in a screen. That distinction is the point: a control that exists only in the interface is a convention, and an auditor will treat it as one.
Purchase invoice · PI-2026-0412
₱248,400.00
Over the approval threshold for this cost centre
Approval
Until the last approval is given, the database refuses to post it — whichever route the request arrives by
Access rules are applied by the database rather than by the interface, so they hold however a request arrives. Removing a button does not remove an endpoint; this does.
The second factor is part of the database access check, not only a screen you pass through. A session that has not completed it reaches no company data at all. Named service accounts and active support sessions are the documented exceptions.
Someone restricted to one entity in a group cannot read another, and that restriction is applied at the same layer as everything else rather than by hiding menu items.
Where an approval rule applies, a document under approval cannot be posted. Precisely: the database refuses the posting; the matching of which rule applies happens in the application.
A posted document cannot be quietly amended by an application user. Corrections are made by a linked reversing entry and both sides stay visible. Support tooling operating with elevated database rights is the documented exception.
Posting into a closed period is refused, with no bypass inside the check itself. Reopening is a deliberate act that records who did it, when, and the reason they gave.
Each recorded action is linked by hash to the one before it. A removed or altered row shows as a break in the sequence, and a check inside the product reports whether the chain still holds. Tamper-evident is the accurate word: this is detection, not prevention.
Every list and report exports to CSV, JSON or Excel. There is no export fee and no notice period on taking your data.
Snapshots are taken automatically and a workspace owner can restore one. A restore takes its own snapshot first, so the state you restored over is still recoverable.
These are real, and they are not ours. We describe them as provider controls so you know where to direct a diligence question.
Provided by our hosting and database platforms as a standard control. We have deliberately removed the specific protocol and cipher versions this page used to quote, because we cannot evidence them from our own configuration.
Authentication is operated by our identity provider. Boongon stores no passwords, and no part of this application handles a raw credential.
Keys and signing secrets are held in the hosting platform’s secret storage rather than in the repository, in build output, or in anything sent to a browser.
The application database runs in Singapore, and there is no choice of region — every customer sits in the same one. Our internal recovery plan sets recovery objectives; those figures are not published here until the owner has confirmed them as commitments we will stand behind.
You will find these out during a procurement review anyway. Finding them here first should cost us less of your goodwill than finding them later.
Boongon does not hold SOC 2, ISO/IEC 27001 or any equivalent, and no audit has been completed. If a certification is a hard requirement for you, say so at the first conversation rather than the last.
We are not publishing the result of an independent penetration test, because there is no completed test to publish.
There is no SAML, OIDC or directory provisioning. Accounts are invited by email and protected by two-step sign-in.
We do not publish an availability figure, because we are not yet measuring one in a way we would be willing to be held to.
Queries run under your own session, so the assistant cannot retrieve a record your permissions exclude. Topic restrictions apply on top of that.
Figures are computed in ordinary code from your records. The model retrieves and explains them. We publish no accuracy statistic because we have not measured one.
It proposes; you approve. An accepted proposal runs through the same approval rules and the same audit trail as work raised by hand.
We do not use your records to train models and we do not sell them. The model provider used for this feature is named in our data-processing documentation on request.
This list previously named two providers. It now names everything the product and this website actually load, including analytics and fonts.
| Provider | Used for |
|---|---|
| Supabase | Application database, authentication and server-side functions |
| Cloudflare | Website hosting, edge network and secret storage |
| Resend | Transactional and contact-form email delivery |
| Google Analytics | Website analytics, loaded only after you accept cookies |
| Google Fonts | Web font delivery on this website |
| Crisp | Website chat, where enabled |
| Frankfurter | Exchange-rate reference data for the currency switcher |
| PayMongo, HitPay and PayPal | Card and wallet payment processing |
A dated list with entity details and locations is available under a data-processing agreement. Ask us on the contact page, or see the list on its own page at subprocessors. Our AI position is set out on responsible AI.
Write to hello@boongon.com with enough detail to reproduce the issue. We will not pursue anyone who reports in good faith, gives us a reasonable chance to fix the problem before disclosing it, and does not access or alter data belonging to anyone else. We are not publishing a response-time commitment, because we have not agreed one internally that we would be comfortable being held to.
We would rather answer it directly than have you infer answers from a marketing page. Anything we cannot evidence, we will tell you we cannot evidence.
Doing a security or compliance review? Ask us anything here, or we can send the written detail.