Features Compliance Pricing Guides About Sign in Start free trial
Security

Security at Boongon.

We're pre-launch. That means we get to build security in from the start, and it means we don't have certificates we haven't earned yet. Here's an honest account of where we are.

Pre-launch posture, formal audits and certifications are in progress, not complete.
What's built today

The technical baseline.

The non-negotiables that have been in place since the first commit.

Encrypted everywhere

TLS 1.3 for data in transit; AES-256 for data at rest. Database backups are encrypted with the same standard and stored in the same legal jurisdiction as the primary.

Hashed passwords

Passwords are stored as salted hashes using a modern, slow algorithm. We never see your plaintext password, and we can't recover it for you, we can only let you reset it.

Secrets, not source

API keys, database credentials, and signing secrets live in Cloudflare Pages secrets, never in the repository, never in build artifacts, never in client-side code.

Least privilege

Only the people who need a piece of data to do their job can see it. Production access is scoped, logged, and reviewed; engineering does not pull customer data into local environments.

Audit trail on writes

Every posted accounting entry carries who, when, and from where. The trail is append-only, corrections are reversing entries, not deletes.

Your data is yours

Export everything you've put in, in open formats, at any time. We do not use your data to train AI models and we do not sell it.

In progress

What we're working on.

Work that's underway. We'll move items off this list as they ship, and we won't claim them until they have.

Frameworks

Compliance frameworks.

Where we stand against the frameworks customers ask about most. Nothing here is exaggerated.

Philippine Data Privacy Act of 2012Privacy notice published, DPO contact in place, breach-notification process drafted. Aligned
GDPR-aware designData-subject rights, lawful basis, and DPA-ready vendor agreements baked into the data model. Aligned
SOC 2 Type IControls mapped, readiness review underway with an independent firm. In progress
ISO/IEC 27001On the post-GA roadmap. We're documenting the ISMS now so the audit doesn't start from zero. Planned
Disclosure

Reporting a vulnerability.

If you believe you've found a security issue in Boongon, write to hello@boongon.com with the details. We'll acknowledge within one business day and keep you in the loop while we work the issue.

Responsible disclosure: please don't access data that isn't yours, don't run automated scans against production, and give us a reasonable window to fix before publishing. We won't pursue good-faith research that follows those lines, and we'll credit reporters who'd like to be named once a fix has shipped.

Security contact

One inbox, watched by people who can act: hello@boongon.com. PGP key available on request.

Subprocessors

Who we share infrastructure with.

A short list while we're small. Each vendor processes data only on our documented instructions, under a Data Processing Agreement.

Cloudflare, application hosting, edge network, secrets management.Asia-Pacific primary region.
Resend, transactional and contact-form email delivery.Used only for outbound messages we initiate.

The full, dated subprocessor list, including any added between now and launch, will be published here before general availability, and we'll notify customers in advance of any changes.

Questions a security review would ask?

Send them over. We'd rather answer them now than after the contract.