Boon for enterprise
Boon holds a SOC 2 Type II attestation, isolates each customer's data at the database level, and works alongside the tools your teams already use. This page covers security, sign-in, rostering, integrations, data handling, and sub-processors.
Security and compliance
- SOC 2 Type II
- Unqualified attestation, Security trust services category, April 1 to June 30, 2026. Report available on request.
- Data isolation
- Every query is scoped to your organization through row-level security in the database, so one customer can never read another's data.
- Encryption
- TLS 1.2 or higher in transit. AES-256 at rest, including backups.
- Access
- Least-privilege, role-based access. Boon staff access to production requires multi-factor authentication.
- Data residency
- Customer data is hosted in the United States. Some participant surveys run through Typeform in the EU.
Full details are on the Security page.
How do people sign in?
- Program admins
- Email and password with a one-time code, or sign in with Google.
- Employees
- A one-time sign-in link sent to their work email. No Boon password to manage.
- SAML SSO and SCIM
- Not currently available.
How are employees added?
Admins add employees in the Boon admin portal, one at a time or in bulk by CSV upload, and deactivate people from the same portal. Boon does not offer a native HRIS sync today. During onboarding, the Boon team can help set up a roster pull from your HRIS.
What does Boon integrate with?
- Slack and Microsoft Teams
- Coaching nudges, reminders, and session prep where your people already work.
- Google and Outlook calendars
- Calendar connection for scheduling sessions.
- Claude and ChatGPT
- Employees can use their coaching program inside AI assistants through Boon's MCP connector.
- Zoom
- Video sessions, where your organization uses it.
How is coaching data handled?
- Confidentiality
- Employers see aggregate participation, themes, and competency trends. Session content stays between coach and participant.
- Recordings
- Boon does not store session recordings.
- AI
- Anthropic is the primary AI provider under zero data retention terms; OpenAI is a fallback with training opted out. Customer data does not train third-party models.
- Breach notification
- Within 72 hours of Boon becoming aware of a personal data breach.
- Deletion
- Customer data is returned or deleted within 90 days of termination.
- Sub-processor changes
- 30 days' advance notice, with 15 days to object.
Which sub-processors does Boon use?
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, server functions | US |
| Amazon Web Services | Infrastructure underlying Supabase | US |
| Vercel | Web application hosting | US, global edge |
| Salesforce | CRM and session scheduling records | US |
| HubSpot | CRM and transactional email | US |
| Sign-in and Google Calendar sync, where used | US | |
| Microsoft | Outlook Calendar sync and Teams app, where used | US |
| Slack | Slack app and operational notifications | US |
| Zoom | Video sessions, where used | US |
| Typeform | Some participant surveys | EU (Spain) |
| Anthropic | Primary AI provider, zero data retention | US |
| OpenAI | Fallback AI provider, training opt-out | US |
| Sentry | Application error monitoring | US |
For the SOC 2 report, our data processing agreement, or a security questionnaire, email security@boon-health.com.
Frequently asked questions
Is Boon SOC 2 compliant?
Boon received an unqualified SOC 2 Type II attestation covering the Security trust services category for April 1 to June 30, 2026. The report is available on request at security@boon-health.com.
Does Boon support SSO and SCIM?
Program admins can sign in with Google, and employees sign in with a one-time email link, so no Boon password is needed. SAML single sign-on through an identity provider such as Okta or Microsoft Entra, and SCIM user provisioning, are not currently available.
Does Boon integrate with our HRIS?
Boon does not offer a native HRIS sync today. Admins add employees in the admin portal, one at a time or by CSV upload, and the Boon team can help set up a roster pull from your HRIS during onboarding.
Where is Boon customer data stored?
In the United States, on Supabase running on AWS, with the web application hosted on Vercel. Some participant surveys run through Typeform in the EU.
How do we get Boon security documentation?
Email security@boon-health.com for the SOC 2 Type II report, the data processing agreement, or help with a security questionnaire.
Request the security packet
SOC 2 Type II report, data processing agreement, and questionnaire support.
Want to know how coaches are selected and results are measured? See Methodology.