BonData is built so the customers we serve, including those in regulated industries, can adopt the platform without compromising on security, privacy, or data residency. This page summarizes the frameworks BonData operates against, the third parties that process data on our behalf, and the policy documents that govern the relationship. Enterprise and regulated-industry customers should deploy via Cloud-Prem on AWS, which runs single-tenant inside the customer’s own AWS account; Cloud SaaS is intended for proofs of concept and lower-tier packages. For the controls behind each framework, see Compliance. For how data flows through the platform, see Application architecture.Documentation Index
Fetch the complete documentation index at: https://docs.bondata.ai/llms.txt
Use this file to discover all available pages before exploring further.
Compliance
SOC 2 Type II
Certified. Audited controls for security, availability, and confidentiality. Report available under NDA via
security@bondata.ai.ISO 27001
Certified. Certificate available under NDA via
security@bondata.ai.GDPR
EU General Data Protection Regulation. DPA with EU Standard Contractual Clauses available.
Subprocessors
BonData uses the following subprocessors to deliver the platform. Each is bound by a written data-processing agreement and is engaged only for the purpose described.| Subprocessor | Purpose | Location | |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: EKS, RDS, S3, Amazon MQ, Secrets Manager, KMS, CloudFront, Athena, Glue, Redshift, CloudWatch | United States (EU on request) | |
| Cloudflare | DNS, TLS termination, web application firewall, DDoS protection, Cloudflare Tunnel | Global edge network | |
| Descope | Identity provider: authentication, SSO federation, SCIM, MFA, session management | United States | |
| Anthropic | Large language model provider (Claude). Inputs and outputs not used for training under Anthropic Commercial Terms. | United States | |
| OpenAI | Large language model provider and default text embeddings (text-embedding-3-small). API usage; not used for training. Enterprise customers can switch embeddings to AWS Bedrock Titan in their Cloud-Prem region. | United States | |
| Large language model provider (Gemini). API usage; not used for training. | United States | ||
| e2b | Sandboxed code execution in ephemeral Firecracker microVMs. Receives the generated code and input variables passed by the workflow node. Compliance posture at trust.e2b.dev. | United States | |
| New Relic | Log aggregation and platform metrics | United States | |
| Sentry | Application error tracking with PII filtering enabled | United States |
Resources
Status Page
Real-time platform availability, incident history, and scheduled maintenance.
Privacy Policy
How BonData collects, uses, and protects personal data.
Terms of Use
The contract that governs use of the BonData platform.
security@bondata.ai.
Ready to evaluate BonData for your enterprise?
Contact us to discuss your security, residency, and compliance requirements and scope the right deployment for your organization. We work with each enterprise to tailor the engagement.