Trust & Security

We hold our own systems to the standard we would ask of you.

Most small firms never document how they run. We do, and we publish it, because an AI practice handles client data and the standard should be visible. Outcomes are below. If you need specifics for a diligence review, ask.

Identity

Every account requires multi-factor sign-in. Older, weaker sign-in methods are turned off. Admin access is limited to what a task needs, with one monitored emergency account and nothing left standing open.

Email

Our domain is fully authenticated (SPF, DKIM, DMARC). Links and attachments are checked before they reach us. Mail cannot auto-forward to outside addresses.

Your files

Anything we share externally requires the recipient to sign in. No anonymous links floating around.

How we run

Every change to our systems is written down and version-controlled, with an audit trail. No quiet clicking in a console.

Secrets

Passwords and keys live in a dedicated vault, never in code or email.

Platform

We build on Microsoft 365 and Azure using their business security tier.


Report something

Security questions, or something to report?

Email security@boundfast.com. Our disclosure contact is also published at /.well-known/security.txt.

security@boundfast.com