Security at Unboredly

    Built with security in every layer.

    Unboredly is designed to protect employee and organizational data through layered access controls, strong authentication, tenant isolation, encrypted cloud infrastructure, secure development practices and continuous security testing.

    Defense in depthSix layers
    Six layers of protection around your data
    1. 01Identity & access
    2. 02Tenant isolation
    3. 03Data protection
    4. 04Secure infrastructure
    5. 05Continuous testing
    6. 06Secure development
    • Authenticator two-factor
    • Tenant isolation
    • Encrypted infrastructure
    • Automated security testing
    • Secure development lifecycle

    Our approach

    Security built in, not bolted on.

    Our architecture uses Google’s cloud security infrastructure for identity and protected data services, and Vercel’s secure platform for application delivery. We add security controls and automated testing built specifically for Unboredly.

    01

    Identity & access

    Strong authentication and access control.

    Unboredly uses secure, identity-based authentication and role-based authorization throughout the platform. Optional authenticator-app two-factor authentication adds a layer of account protection beyond passwords.

    Access decisions are enforced at the data layer, not simply by hiding features in the interface. Administrator, manager and employee capabilities are separated according to their responsibilities.

    • Authenticator-app two-factor
    • Role-based access control
    • Data-layer authorization
    • Email verification
    • Automatic sign-out after inactivity
    02

    Tenant isolation

    Organization-level data isolation.

    Unboredly is a multi-tenant platform with authorization controls that keep each organization’s data separate. Access is evaluated using authenticated identity, organization membership and role before any protected data operation is allowed.

    We maintain automated authorization tests designed specifically to catch cross-organization access and privilege-boundary regressions.

    • Organization-scoped access
    • Cross-organization regression tests
    • Privilege-boundary tests
    03

    Data protection

    Protected by modern cloud infrastructure.

    Unboredly uses Google cloud services for identity, application data and storage, and benefits from Google’s mature security infrastructure and built-in encryption.

    Google encrypts customer content at rest by default, using AES-256 at the storage layer, and protects data in transit. Every Unboredly page and request is served over HTTPS (TLS).

    • Encrypted at rest (AES-256)
    • HTTPS / TLS in transit
    • Google cloud security infrastructure
    04

    Secure infrastructure

    Secure application delivery.

    Unboredly’s application is delivered on Vercel’s platform, which provides secure HTTPS delivery and modern cloud deployment infrastructure.

    Vercel encrypts data at rest with AES-256 and uses TLS for data in transit.

    • HTTPS delivery
    • Encrypted at rest and in transit
    • Modern cloud deployment
    05

    Continuous testing

    Continuous vulnerability testing.

    Automated dynamic application security testing is part of how we build. Unboredly’s public application is scanned with OWASP ZAP every week and whenever the codebase changes, to find common web security weaknesses and configuration issues.

    This scanning complements the automated application and authorization tests we run during development.

    • OWASP ZAP security scanning
    • Weekly and on every code change
    • Web configuration checks
    06

    Secure development

    Security tested with every change.

    Security checks are built into Unboredly’s development lifecycle. Every change runs automated build, application, authorization and end-to-end tests.

    Security-sensitive features have dedicated regression tests, so weaknesses we have fixed and authorization rules we rely on stay that way.

    • Security regression tests
    • Authorization boundary tests
    • End-to-end application tests
    • Automated CI/CD checks

    Also built in

    Protected file handling

    File access is governed by authenticated identity, organization boundaries and application authorization policies. Upload restrictions and storage access controls are tested as part of our security regression suite.

    Security event visibility

    Security-sensitive actions are designed with accountability in mind. Unboredly records security-relevant events for supported workflows, such as turning two-factor authentication on or off and removing an employee.

    Defense in depth

    Unboredly doesn’t rely on a single control. Identity verification, role authorization, organization isolation, data-layer permissions, secure cloud infrastructure, automated testing and vulnerability scanning work together as independent layers.

    Certifications

    Clear about what’s certified.

    Google Cloud and Vercel maintain independent certifications for their platforms, including SOC 2 Type II and ISO/IEC 27001. Those cover their infrastructure, not Unboredly itself.

    Unboredly has not yet completed its own audit. As we grow, we plan to pursue formal certification based on what our customers need, and we will say so here when we have it.

    Smart features

    Only what the feature needs.

    Some features, such as drafting onboarding plans and summaries, are processed by Anthropic and OpenAI. We send only what the feature needs, only to deliver it. By default, neither provider uses data sent through its API to train its models.

    Your data

    Your organization owns its data.

    Unboredly processes your data to provide the service. We don’t claim ownership of your content, onboarding materials or internal information.

    Always improving

    Security is an ongoing process.

    We keep evaluating and improving Unboredly’s security controls as the platform evolves. Automated security testing, authorization regression testing and vulnerability scanning help us find weaknesses before they become customer problems.

    Questions about security or how we handle data? We’re happy to help.