Boon for enterprise
Boon holds a SOC 2 Type II attestation, isolates each customer's data at the database level, and works alongside the tools your teams already use. This page covers security, sign-in, rostering, integrations, data handling, and sub-processors.
Security and compliance
- SOC 2 Type II
- Unqualified attestation, Security trust services category, April 1 to June 30, 2026. Report available on request.
- Data isolation
- Every query is scoped to your organization through row-level security in the database, so one customer can never read another's data.
- Encryption
- TLS 1.2 or higher in transit. AES-256 at rest, including backups.
- Access
- Least-privilege, role-based access. Boon staff access to production requires multi-factor authentication.
- Data residency
- Customer data is hosted in the United States. Some participant surveys run through Typeform in the EU.
Full details are on the Security page.
How do people sign in?
- Program admins
- Email and password with a one-time code, or sign in with Google.
- Employees
- A one-time sign-in link sent to their work email. No Boon password to manage.
- SAML SSO and SCIM
- Not currently available.
How are employees added?
Admins add employees in the Boon admin portal, one at a time or in bulk by CSV upload, and deactivate people from the same portal. Boon does not offer a native HRIS sync today. During onboarding, the Boon team can help set up a roster pull from your HRIS.
What does Boon integrate with?
- Slack and Microsoft Teams
- Coaching nudges, reminders, and session prep where your people already work.
- Google and Outlook calendars
- Calendar connection for scheduling sessions.
- Claude and ChatGPT
- Employees can use their coaching program inside Claude or ChatGPT through Boon's MCP connector, after signing in with a one-time code sent to their work email. Boon returns only that employee's own coaching data, and logs which tool was used, never the conversation. The conversation itself runs on the employee's or employer's Claude or ChatGPT account and falls under that account's AI terms, not Boon's. The one exception is conversation rehearsal, which Boon runs on its own AI provider under the terms below.
- Zoom
- Video sessions, where your organization uses it.
How is coaching data handled?
- Confidentiality
- Employers see aggregate participation, themes, and competency trends. Session content stays between coach and participant.
- Recordings and transcripts
- Boon creates Zoom sessions with recording off, and does not record, transcribe, or store coaching sessions.
- Session notes
- Coaches keep short notes in Boon to follow up between sessions. Notes are visible to the coach and Boon's operations team only, and are never shared with your organization.
- AI
- Boon's AI features work from structured program data, such as goals, themes, action items, and survey scores, and from a coach's own notes when the coach asks for help tidying them. No session audio or transcript reaches an AI model. Anthropic is the primary AI provider under zero data retention terms; OpenAI is a fallback with training opted out. Customer data does not train third-party models.
- Breach notification
- Within 72 hours of Boon becoming aware of a personal data breach.
- Deletion
- Customer data is returned or deleted within 90 days of termination.
- Sub-processor changes
- 30 days' advance notice, with 15 days to object.
Which sub-processors does Boon use?
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, server functions | US |
| Amazon Web Services | Infrastructure underlying Supabase | US |
| Vercel | Web application hosting | US, global edge |
| Salesforce | CRM and session scheduling records | US |
| HubSpot | CRM and transactional email | US |
| Sign-in and Google Calendar sync, where used | US | |
| Microsoft | Outlook Calendar sync and Teams app, where used | US |
| Slack | Slack app and operational notifications | US |
| Zoom | Video sessions, where used | US |
| Typeform | Some participant surveys | EU (Spain) |
| Anthropic | Primary AI provider, zero data retention | US |
| OpenAI | Fallback AI provider, training opt-out | US |
| Perplexity | Public web lookup of your company name for coach matching and program insights; no personal data is sent | US |
| Sentry | Application error monitoring | US |
| Stripe | Payments for individual self-paid purchases only; does not process enterprise customer data | US |
For the SOC 2 report, our data processing agreement, or a security questionnaire, email security@boon-health.com.
Frequently asked questions
Is Boon SOC 2 compliant?
Boon received an unqualified SOC 2 Type II attestation covering the Security trust services category for April 1 to June 30, 2026. The report is available on request at security@boon-health.com.
Does Boon support SSO and SCIM?
Program admins can sign in with Google, and employees sign in with a one-time email link, so no Boon password is needed. SAML single sign-on through an identity provider such as Okta or Microsoft Entra, and SCIM user provisioning, are not currently available.
Does Boon integrate with our HRIS?
Boon does not offer a native HRIS sync today. Admins add employees in the admin portal, one at a time or by CSV upload, and the Boon team can help set up a roster pull from your HRIS during onboarding.
Where is Boon customer data stored?
In the United States, on Supabase running on AWS, with the web application hosted on Vercel. Some participant surveys run through Typeform in the EU.
How do we get Boon security documentation?
Email security@boon-health.com for the SOC 2 Type II report, the data processing agreement, or help with a security questionnaire.
Request the security packet
SOC 2 Type II report, data processing agreement, and questionnaire support.
Want to know how coaches are selected and results are measured? See Methodology.