Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.bondata.ai/llms.txt

Use this file to discover all available pages before exploring further.

BonData is built so the customers we serve, including those in regulated industries, can adopt the platform without compromising on security, privacy, or data residency. This page summarizes the frameworks BonData operates against, the third parties that process data on our behalf, and the policy documents that govern the relationship. Enterprise and regulated-industry customers should deploy via Cloud-Prem on AWS, which runs single-tenant inside the customer’s own AWS account; Cloud SaaS is intended for proofs of concept and lower-tier packages. For the controls behind each framework, see Compliance. For how data flows through the platform, see Application architecture.

Compliance

SOC 2 Type II

Certified. Audited controls for security, availability, and confidentiality. Report available under NDA via security@bondata.ai.

ISO 27001

Certified. Certificate available under NDA via security@bondata.ai.

GDPR

EU General Data Protection Regulation. DPA with EU Standard Contractual Clauses available.

Subprocessors

BonData uses the following subprocessors to deliver the platform. Each is bound by a written data-processing agreement and is engaged only for the purpose described.
SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure: EKS, RDS, S3, Amazon MQ, Secrets Manager, KMS, CloudFront, Athena, Glue, Redshift, CloudWatchUnited States (EU on request)
CloudflareDNS, TLS termination, web application firewall, DDoS protection, Cloudflare TunnelGlobal edge network
DescopeIdentity provider: authentication, SSO federation, SCIM, MFA, session managementUnited States
AnthropicLarge language model provider (Claude). Inputs and outputs not used for training under Anthropic Commercial Terms.United States
OpenAILarge language model provider and default text embeddings (text-embedding-3-small). API usage; not used for training. Enterprise customers can switch embeddings to AWS Bedrock Titan in their Cloud-Prem region.United States
GoogleLarge language model provider (Gemini). API usage; not used for training.United States
e2bSandboxed code execution in ephemeral Firecracker microVMs. Receives the generated code and input variables passed by the workflow node. Compliance posture at trust.e2b.dev.United States
New RelicLog aggregation and platform metricsUnited States
SentryApplication error tracking with PII filtering enabledUnited States
For Cloud-Prem deployments, AWS, Cloudflare, and Descope are still in scope; the remaining subprocessors are engaged only when the corresponding feature (a given AI model, code execution, hosted observability) is enabled by the customer.

Resources

Status Page

Real-time platform availability, incident history, and scheduled maintenance.

Privacy Policy

How BonData collects, uses, and protects personal data.

Terms of Use

The contract that governs use of the BonData platform.
For SOC 2 Type II reports, Data Processing Agreements, security questionnaires, or penetration test summaries, contact security@bondata.ai.

Ready to evaluate BonData for your enterprise?

Contact us to discuss your security, residency, and compliance requirements and scope the right deployment for your organization. We work with each enterprise to tailor the engagement.