Bosmos
Log inStart for free

Security at Bosmos

Last updated: September 30, 2026

Bosmos, Inc. ("Bosmos") connects to business mailboxes, calendars, contacts, and CRM systems, so protecting that information is central to how we build and operate the Services. This page summarizes the administrative, technical, and organizational safeguards we use. It is a description of our program, not a contract, and it works alongside our Privacy Policy and Terms of Service.

Encryption

  • Data is encrypted in transit using TLS between your browser, Bosmos, and the services we connect to.
  • Data is encrypted at rest in our managed database and storage providers.
  • OAuth access and refresh tokens for connected accounts are stored in access-controlled systems and are never sent to analytics or session-replay providers.

Authentication and access control

  • Access to a workspace's data is scoped by workspace-based authorization, so people only see what their role allows.
  • Production access is limited to authorized personnel with a business need and is subject to access controls.
  • Bosmos personnel do not access connected mailbox content unless you authorize review of specific content for support, access is necessary to investigate abuse or a security incident, or access is required by law.

Data minimization and AI handling

  • Bosmos does not sell connected account data and does not use it for advertising or eligibility decisions.
  • Bosmos does not use Google or Microsoft user data, or data derived from it, to train, retrain, or improve any general-purpose, foundation, or shared AI or machine-learning model.
  • AI-assisted requests are routed through the Vercel AI Gateway to the configured model provider only to produce the specific feature you requested.
  • Connected mailbox content, message bodies, subject lines, addresses, attachments, and credentials are excluded from product analytics and session replay.

Infrastructure and subprocessors

Bosmos runs on vetted infrastructure providers and uses subprocessors only for defined business and technical purposes, including Vercel (hosting, infrastructure, analytics, and AI request routing), Supabase (authentication, databases, and storage), OpenAI and DeepSeek (model processing via the Vercel AI Gateway), PostHog (product analytics and session replay, with the exclusions above), and Braintree (payment processing). See the Privacy Policy for how these providers process information.

Software and dependency security

  • Changes go through code review before release.
  • We review software and third-party dependencies and apply updates for known vulnerabilities.
  • We monitor the Services for reliability and signs of abuse.

Data retention and deletion

When a person is removed from a workspace, we immediately revoke their workspace access and stored Google and Microsoft mailbox tokens, and we delete the associated retained mailbox records on the schedule described in our Privacy Policy. You can revoke Bosmos's access to a connected account at any time through the provider's permissions page, and you can delete your account through the available account controls.

Incident response

No service can guarantee absolute security. If Bosmos learns of unauthorized access to connected account data, we will investigate, take steps to contain the incident, and provide notifications when required by law or applicable provider requirements.

Reporting a vulnerability

If you believe you have found a security issue, please contact us at info@bosmos.org with enough detail to reproduce the issue. Please do not publicly disclose a potential vulnerability until we have had a reasonable opportunity to investigate and address it. We appreciate responsible disclosure.

Contact

Bosmos, Inc.

285 W Wieuca Rd NE, STE 69184, Atlanta, GA 30342, United States

Email: info@bosmos.org