For IT and procurement

Boon for enterprise

Boon holds a SOC 2 Type II attestation, isolates each customer's data at the database level, and works alongside the tools your teams already use. This page covers security, sign-in, rostering, integrations, data handling, and sub-processors.

Security and compliance

SOC 2 Type II
Unqualified attestation, Security trust services category, April 1 to June 30, 2026. Report available on request.
Data isolation
Every query is scoped to your organization through row-level security in the database, so one customer can never read another's data.
Encryption
TLS 1.2 or higher in transit. AES-256 at rest, including backups.
Access
Least-privilege, role-based access. Boon staff access to production requires multi-factor authentication.
Data residency
Customer data is hosted in the United States. Some participant surveys run through Typeform in the EU.

Full details are on the Security page.

How do people sign in?

Program admins
Email and password with a one-time code, or sign in with Google.
Employees
A one-time sign-in link sent to their work email. No Boon password to manage.
SAML SSO and SCIM
Not currently available.

How are employees added?

Admins add employees in the Boon admin portal, one at a time or in bulk by CSV upload, and deactivate people from the same portal. Boon does not offer a native HRIS sync today. During onboarding, the Boon team can help set up a roster pull from your HRIS.

What does Boon integrate with?

Slack and Microsoft Teams
Coaching nudges, reminders, and session prep where your people already work.
Google and Outlook calendars
Calendar connection for scheduling sessions.
Claude and ChatGPT
Employees can use their coaching program inside Claude or ChatGPT through Boon's MCP connector, after signing in with a one-time code sent to their work email. Boon returns only that employee's own coaching data, and logs which tool was used, never the conversation. The conversation itself runs on the employee's or employer's Claude or ChatGPT account and falls under that account's AI terms, not Boon's. The one exception is conversation rehearsal, which Boon runs on its own AI provider under the terms below.
Zoom
Video sessions, where your organization uses it.

How is coaching data handled?

Confidentiality
Employers see aggregate participation, themes, and competency trends. Session content stays between coach and participant.
Recordings and transcripts
Boon creates Zoom sessions with recording off, and does not record, transcribe, or store coaching sessions.
Session notes
Coaches keep short notes in Boon to follow up between sessions. Notes are visible to the coach and Boon's operations team only, and are never shared with your organization.
AI
Boon's AI features work from structured program data, such as goals, themes, action items, and survey scores, and from a coach's own notes when the coach asks for help tidying them. No session audio or transcript reaches an AI model. Anthropic is the primary AI provider under zero data retention terms; OpenAI is a fallback with training opted out. Customer data does not train third-party models.
Breach notification
Within 72 hours of Boon becoming aware of a personal data breach.
Deletion
Customer data is returned or deleted within 90 days of termination.
Sub-processor changes
30 days' advance notice, with 15 days to object.

Which sub-processors does Boon use?

Sub-processorPurposeLocation
SupabaseDatabase, authentication, server functionsUS
Amazon Web ServicesInfrastructure underlying SupabaseUS
VercelWeb application hostingUS, global edge
SalesforceCRM and session scheduling recordsUS
HubSpotCRM and transactional emailUS
GoogleSign-in and Google Calendar sync, where usedUS
MicrosoftOutlook Calendar sync and Teams app, where usedUS
SlackSlack app and operational notificationsUS
ZoomVideo sessions, where usedUS
TypeformSome participant surveysEU (Spain)
AnthropicPrimary AI provider, zero data retentionUS
OpenAIFallback AI provider, training opt-outUS
PerplexityPublic web lookup of your company name for coach matching and program insights; no personal data is sentUS
SentryApplication error monitoringUS
StripePayments for individual self-paid purchases only; does not process enterprise customer dataUS

For the SOC 2 report, our data processing agreement, or a security questionnaire, email security@boon-health.com.

Frequently asked questions

Is Boon SOC 2 compliant?

Boon received an unqualified SOC 2 Type II attestation covering the Security trust services category for April 1 to June 30, 2026. The report is available on request at security@boon-health.com.

Does Boon support SSO and SCIM?

Program admins can sign in with Google, and employees sign in with a one-time email link, so no Boon password is needed. SAML single sign-on through an identity provider such as Okta or Microsoft Entra, and SCIM user provisioning, are not currently available.

Does Boon integrate with our HRIS?

Boon does not offer a native HRIS sync today. Admins add employees in the admin portal, one at a time or by CSV upload, and the Boon team can help set up a roster pull from your HRIS during onboarding.

Where is Boon customer data stored?

In the United States, on Supabase running on AWS, with the web application hosted on Vercel. Some participant surveys run through Typeform in the EU.

How do we get Boon security documentation?

Email security@boon-health.com for the SOC 2 Type II report, the data processing agreement, or help with a security questionnaire.

Request the security packet

SOC 2 Type II report, data processing agreement, and questionnaire support.

Email security@boon-health.com

Want to know how coaches are selected and results are measured? See Methodology.