Request a demo
Platform Overview Finance Sales and CRM Procurement and Inventory Projects and Service People and Payroll Ask Boongon Boongon BusinessBoongon Enterprise
Solutions Construction Facilities Management Service and Repair Hospitality Distribution
Why Boongon Why Boongon Security Integrations Move to Boongon Implementation Compliance
Resources Blog Help Roadmap Changelog Status
Company About Contact
Pricing Sign in
Security

What we can show you, and what we cannot.

This page separates three things: controls enforced in our own code, controls our platform providers operate, and things that are simply not in place yet. Mixing those together is how security pages mislead people.

Why this page got shorter

It previously described a certification readiness assessment, a scheduled external penetration test, specific encryption versions and a response-time commitment. None of those could be evidenced, so they have been removed rather than reworded. We would rather publish less and have all of it be true.

Colleagues around a table examining a printed statement
Every approval names a person, and the record of it cannot be edited afterwards.

A control you can point at

Approvals are enforced where the data lives, not by hiding a button. Every one names the person who gave it and the moment they did, and a posted record cannot be quietly edited afterwards — a correction is a new entry that leaves both visible.

Enforced in the product

Controls that hold when the interface is not involved.

Each of these is implemented in the application and the database rather than in a screen. That distinction is the point: a control that exists only in the interface is a convention, and an auditor will treat it as one.

Purchase invoice · PI-2026-0412

₱248,400.00

Over the approval threshold for this cost centre

Approval

  1. Site manager Approved
  2. Commercial Approved
  3. Finance director Waiting

Until the last approval is given, the database refuses to post it — whichever route the request arrives by

Process illustration · demonstration data The distinction, drawn: the refusal is a property of the record, not of the screen you happened to use.

Permissions live with the data

Access rules are applied by the database rather than by the interface, so they hold however a request arrives. Removing a button does not remove an endpoint; this does.

Two-step sign-in reaches into the database

The second factor is part of the database access check, not only a screen you pass through. A session that has not completed it reaches no company data at all. Named service accounts and active support sessions are the documented exceptions.

Access can be limited to named companies

Someone restricted to one entity in a group cannot read another, and that restriction is applied at the same layer as everything else rather than by hiding menu items.

Approval blocks posting

Where an approval rule applies, a document under approval cannot be posted. Precisely: the database refuses the posting; the matching of which rule applies happens in the application.

Posted records are corrected, not edited

A posted document cannot be quietly amended by an application user. Corrections are made by a linked reversing entry and both sides stay visible. Support tooling operating with elevated database rights is the documented exception.

A closed period stays closed

Posting into a closed period is refused, with no bypass inside the check itself. Reopening is a deliberate act that records who did it, when, and the reason they gave.

Activity is tamper-evident

Each recorded action is linked by hash to the one before it. A removed or altered row shows as a break in the sequence, and a check inside the product reports whether the chain still holds. Tamper-evident is the accurate word: this is detection, not prevention.

Your data comes out whenever you want it

Every list and report exports to CSV, JSON or Excel. There is no export fee and no notice period on taking your data.

Backups you can restore yourself

Snapshots are taken automatically and a workspace owner can restore one. A restore takes its own snapshot first, so the state you restored over is still recoverable.

Operated by our platform providers

Controls we rely on rather than build.

These are real, and they are not ours. We describe them as provider controls so you know where to direct a diligence question.

Not in place today

The gaps, stated plainly.

You will find these out during a procurement review anyway. Finding them here first should cost us less of your goodwill than finding them later.

Ask Boongon

How the assistant handles your data.

It reads as you

Queries run under your own session, so the assistant cannot retrieve a record your permissions exclude. Topic restrictions apply on top of that.

It does not calculate

Figures are computed in ordinary code from your records. The model retrieves and explains them. We publish no accuracy statistic because we have not measured one.

It cannot commit anything

It proposes; you approve. An accepted proposal runs through the same approval rules and the same audit trail as work raised by hand.

Your records are not training material

We do not use your records to train models and we do not sell them. The model provider used for this feature is named in our data-processing documentation on request.

Subprocessors

Everyone who touches data on our behalf.

This list previously named two providers. It now names everything the product and this website actually load, including analytics and fonts.

Subprocessors and what each is used for
ProviderUsed for
Supabase Application database, authentication and server-side functions
Cloudflare Website hosting, edge network and secret storage
Resend Transactional and contact-form email delivery
Google Analytics Website analytics, loaded only after you accept cookies
Google Fonts Web font delivery on this website
Crisp Website chat, where enabled
Frankfurter Exchange-rate reference data for the currency switcher
PayMongo, HitPay and PayPal Card and wallet payment processing

A dated list with entity details and locations is available under a data-processing agreement. Ask us on the contact page, or see the list on its own page at subprocessors. Our AI position is set out on responsible AI.

Reporting a vulnerability

Write to hello@boongon.com with enough detail to reproduce the issue. We will not pursue anyone who reports in good faith, gives us a reasonable chance to fix the problem before disclosing it, and does not access or alter data belonging to anyone else. We are not publishing a response-time commitment, because we have not agreed one internally that we would be comfortable being held to.

Bring your security questionnaire.

We would rather answer it directly than have you infer answers from a marketing page. Anything we cannot evidence, we will tell you we cannot evidence.