Back to home

Security

Security is foundational to how BoltAI is built and operated. We take a rigorous, layered approach to protect your business data.

Encryption

All data is encrypted in transit using TLS 1.2 or higher, protecting information as it moves between your devices, our servers, and third-party services like Gmail and Google Calendar. Data stored at rest is protected with AES-256 encryption on secure cloud infrastructure.

Access Controls

Access to BoltAI systems is restricted to authorized personnel and requires multi-factor authentication. We follow the principle of least privilege — employees and contractors have access only to the systems and data needed for their role. All access is logged and reviewed regularly.

Compliance

BoltAI operates on US-based infrastructure with SOC 2 Type II compliance. This means our systems, processes, and and controls have been independently audited to meet rigorous security and availability standards. We undergo annual third-party security assessments.

AI Processing

All AI email processing happens on US-based infrastructure. Your email content is used only to provide the BoltAI service and is never used to train or improve AI models. Automated decisions (email drafts, appointment confirmations) are made by models configured to act within the parameters you set during setup.

Incident Response

If a security incident occurs, our team will notify affected users within 72 hours of confirmation. We maintain a documented incident response plan and conduct regular drills to ensure we can act quickly and transparently.

Report a Vulnerability

If you discover a security concern, contact us at boltai-2@polsia.app with details. We appreciate responsible disclosure and aim to respond within 24 hours on business days.