Trust & Security
We hold our own systems to the standard we would ask of you.
Most small firms never document how they run. We do, and we publish it, because an AI practice handles client data and the standard should be visible. Outcomes are below. If you need specifics for a diligence review, ask.
Identity
Every account requires multi-factor sign-in. Older, weaker sign-in methods are turned off. Admin access is limited to what a task needs, with one monitored emergency account and nothing left standing open.
Our domain is fully authenticated (SPF, DKIM, DMARC). Links and attachments are checked before they reach us. Mail cannot auto-forward to outside addresses.
Your files
Anything we share externally requires the recipient to sign in. No anonymous links floating around.
How we run
Every change to our systems is written down and version-controlled, with an audit trail. No quiet clicking in a console.
Secrets
Passwords and keys live in a dedicated vault, never in code or email.
Platform
We build on Microsoft 365 and Azure using their business security tier.
Report something
Security questions, or something to report?
Email security@boundfast.com. Our disclosure contact is also published at /.well-known/security.txt.
security@boundfast.com