Acceptable use
What Boreon is for, how to use it well, and the small number of things it may not be used for.
Updated
Who this applies to
This policy applies to everybody who uses Boreon, on either edition, and to anybody using this website.
If your organisation holds the license or the subscription, your organisation is responsible for the people it lets in, including contractors working for you. That is not a way of shifting blame. It is simply where the control sits: you create the accounts, so you decide who has one.
What the product is for
Boreon governs a Tableau environment you are responsible for. It traces where a number came from, shows what a change will reach before you make it, finds personal data before somebody else does, moves content between sites under approval, hands over the work of somebody who has left, and produces the evidence an auditor asks for.
It reads first and changes nothing on its own. Every change goes through a gate with a person on it. Used the way it is built, this policy is something you will never think about again.
Connect only what you are entitled to connect
Sign in with your own Tableau token, and connect only the Tableau sites and warehouses your organisation is entitled to reach.
Your own permissions come with you. We inherit what your Tableau environment already grants you and what your warehouse role already allows, and we never widen either. So the boundary you already administer is the boundary here.
That also means the product cannot be used to reach around a permission you do not have. If you think you have found a way, that is a vulnerability report and the section below tells you where to send it.
Look after your credentials
- One account per person. Shared logins destroy the audit trail, which is the one thing this product exists to produce.
- Keep your authenticator tool to yourself. Both factors are required every time, and that is a feature rather than an obstacle.
- Never use somebody else’s Tableau token, and never paste one into an account that is not yours.
- Tell an administrator the moment you think an account or a token has been exposed. Disabling an account ends every live session it holds on the next request.
Using the AI well
AI is optional, it runs on the key you supply, and it is advisory. It reads, explains and drafts, and anything that would change something arrives as a card for a person to approve.
Two responsibilities come with switching it on, and neither is onerous:
- What you send is governed by your own contract with your provider. Do not send content your own policy forbids leaving your network. If that is a hard boundary for you, point the key at your own endpoint and nothing leaves it.
- Read what it drafts before you approve it. A model that explains a governance finding is useful. A governance decision nobody read is not, whoever or whatever drafted it.
Every application produces its full result without AI, so leaving it off is always a complete option rather than a degraded one.
What the product may not be used for
Short list, and each line is here because it would harm somebody:
- Reaching data you have no right to, whether by using another person’s credential or by any other means.
- Working around an approval gate, an audit record, or the dual-control rules your own governance team set.
- Attacking, overloading or probing the hosted service, or attempting to reach another customer’s tenant.
- Uploading malicious code, or using the product to distribute it.
- Giving somebody outside your organisation access to the product, or running it as a service for them.
- Anything unlawful, and anything that would put Boreon in breach of the law.
The license covers redistribution, resale and reverse engineering separately. This list is about conduct, not about license scope.
Reasonable use of the hosted service
Boreon Cloud is shared infrastructure operated for real work, including scans that legitimately read a great deal at once. Heavy use is expected and is not a problem.
What we ask is that automated use stays proportionate, so that one account does not degrade the service for another. If you are planning something unusually large, tell us first and we will help you schedule it rather than discover it.
There is no published rate limit to design around. If your work needs more than proportionate use, tell us what you are planning and we will size for it rather than throttle you for it.
Reporting a vulnerability
If you find a security problem, we want the report. Send it to privacy@boreon.com with enough detail to reproduce it, and we will come back to you.
Please test only against your own tenant and your own data, never against another customer, and please give us a chance to fix the issue before you publish it.
Research done in good faith, within those bounds, is welcome, and we will not pursue you for it.
If this policy is breached
The first step is a conversation. Most breaches of a policy like this one are misunderstandings, and a misunderstanding is fixed by explaining it.
Where something is causing active harm, to another customer, to the service, or to somebody’s data, we may act first and explain immediately afterwards. Suspension is a last resort and it is not a commercial instrument.
How suspension and reinstatement work, and how this policy sits alongside the termination rights in your agreement, are set out in that agreement. Where the two differ, the agreement governs.
Questions about this policy go to privacy@boreon.com.