Skip to content

Where your data sits, and who can reach it

The answers a security review asks for, in the order it asks for them.

Nothing changes until a person says so.

You hold the pen

The AI reads, explains and proposes. Anything it suggests arrives as a card that routes into the same approval gate a person would use, with the same signature and dual-control rules. Publishing always creates a new copy and never overwrites your work.

Where it runs, and who decides that

The hosted edition runs on dedicated infrastructure, in a cloud and a region you pick, with a web application firewall in front of it. The Enterprise License is the same container standing in any major cloud you already run, or inside your own network. Residency stays your decision. The four facts underneath are the shape of the deployment rather than its coordinates.

One supervised container
The service runs as a Docker Swarm stack. One published entry point fronts the whole platform. Each governed tool is bound to the loopback interface inside the box. Only the gateway that supervises it can reach it.
A web application firewall in front
Traffic passes an open-appsec web application firewall in blocking mode before the service sees it. It is the first thing any probe meets.
The cloud is your decision
It is one container on ordinary infrastructure. It stands in any major cloud you already use, or inside your own network. Which one it stands in is settled by you, not by the product.

Connect a warehouse without giving up write access.

Read only, by construction

The connectors contain no write method at all, so a read-only credential is all TabTotal ever needs. Whatever your role cannot see, Boreon cannot see either.

Who can reach it, and for how long

Identity is either ours or yours, and an access change takes effect while you are still talking about it.

  1. Two factors, or your own provider

    Sign in with a managed username and password, plus a required authenticator tool. Or use SAML 2.0 against the identity provider your organisation already runs. Both stay available. Single sign-on ships dormant until an admin connects a provider.

  2. One organisation, one identity provider

    Connections are keyed by email domain. A work address resolves to that organisation’s own provider, and the assertion is checked against that organisation’s own certificate. An assertion signed for one customer can never mint a session for another.

  3. Roles read fresh on every request

    Admin rights are re-read from the directory each time they are used. A role never travels inside a token. There is no cached copy waiting to expire.

  4. Access changes land on the next request

    Disable a person, rotate a password or reset an authenticator. Every live session they hold ends the next time it is used, not at token expiry.

  5. Two timers, running at once

    A session closes itself after half an hour of no activity. A separate hard cap ends it after twelve hours, whatever the day looked like. Activity slides the first timer and leaves the second where it was.

What happens to your credentials

They stay on the server, for the life of a session, and the browser never sees one.

Your secrets stay on the server

Your Tableau token and every warehouse credential stay on the server. They are held for the life of the session. The page gets two things: whether you are signed in, and which address you used.

Held for a session, and gone with it

A credential supplied for a session lives in memory for that session. That is how the software is built, not a retention policy.

Anything stored is encrypted and never echoed

A credential you choose to keep is encrypted at rest. The key is made for that purpose alone. The file is written in one step, with owner-only permissions, and listed by name. The console shows you that it exists, and never what it is.

Read only, by construction

The warehouse connectors hold no write method at all. A read-only credential is everything TabTotal ever needs. The product sees what your own role sees, and no more.

Your permissions, inherited and never widened

You sign in to Tableau with your own token. Your own permissions apply, and the product reads what you can read.

It depends on whose machine it is

Most of a hosted-service questionnaire does not apply to software running inside your own network. Pick the column you are reviewing.

Boreon’s TabTotal Cloud

Boreon runs the service on infrastructure it operates for you, and is the processor for what you put in it.

  • Dedicated infrastructure, behind a web application firewall in blocking mode.
  • The container runs as a normal user account, never as root.
  • Security headers on every response. Every change carries a request token bound to your session.
  • Sign-in is rate limited, and locked out per account and per address.
  • The published sub-processor list applies here.

Enterprise License

The same software runs inside your own network. Your organisation holds the admin account, and your content never reaches us. Most of a hosted-service questionnaire does not apply.

  • Everything stays on your machines. There is nothing for us to keep.
  • We engage no sub-processor for your data, because we never hold it.
  • Identity is your own provider. The session rules are the same ones set out here.
  • The same hardened image, the same audit trail, the same read-only warehouse connectors.
  • Your own retention policy governs, because the files are on your machines.

What the assistant is allowed to do

Every application produces its complete result on its own deterministic engine. The strongest sovereignty statement here is therefore not a residency clause: you can leave the assistant switched off and lose nothing.

Complete with no model at all
Every tool produces its full result on its own deterministic engine. Leave AI switched off and the product is still complete, and nothing leaves the deployment it runs in.
Your key, your provider, your terms
Switch it on and it runs on the key you supplied, with the provider you chose, under your own contract. Boreon supplies no key and keeps no shared pool. Your model provider is yours, rather than our sub-processor.
It advises, and a person applies
The assistant has no write path. What it proposes arrives as a card. That card routes into the same approval gate a person would use, with the same signature rules.
Your content stays out of training
Your content trains nothing, by us or on our instruction. What your own provider does sits under the contract you hold with them.

The documents behind all of this

The sub-processor list and the data processing summary are the two a review usually needs first.

Send this page to your reviewer

If a question here is unanswered, ask us and we will answer it rather than route you to a form.