Your secrets stay on the server
Your Tableau token and every warehouse credential stay on the server. They are held for the life of the session. The page gets two things: whether you are signed in, and which address you used.
The answers a security review asks for, in the order it asks for them.
Nothing changes until a person says so.
The AI reads, explains and proposes. Anything it suggests arrives as a card that routes into the same approval gate a person would use, with the same signature and dual-control rules. Publishing always creates a new copy and never overwrites your work.
The hosted edition runs on dedicated infrastructure, in a cloud and a region you pick, with a web application firewall in front of it. The Enterprise License is the same container standing in any major cloud you already run, or inside your own network. Residency stays your decision. The four facts underneath are the shape of the deployment rather than its coordinates.
Connect a warehouse without giving up write access.
The connectors contain no write method at all, so a read-only credential is all TabTotal ever needs. Whatever your role cannot see, Boreon cannot see either.
Identity is either ours or yours, and an access change takes effect while you are still talking about it.
Sign in with a managed username and password, plus a required authenticator tool. Or use SAML 2.0 against the identity provider your organisation already runs. Both stay available. Single sign-on ships dormant until an admin connects a provider.
Connections are keyed by email domain. A work address resolves to that organisation’s own provider, and the assertion is checked against that organisation’s own certificate. An assertion signed for one customer can never mint a session for another.
Admin rights are re-read from the directory each time they are used. A role never travels inside a token. There is no cached copy waiting to expire.
Disable a person, rotate a password or reset an authenticator. Every live session they hold ends the next time it is used, not at token expiry.
A session closes itself after half an hour of no activity. A separate hard cap ends it after twelve hours, whatever the day looked like. Activity slides the first timer and leaves the second where it was.
They stay on the server, for the life of a session, and the browser never sees one.
Your Tableau token and every warehouse credential stay on the server. They are held for the life of the session. The page gets two things: whether you are signed in, and which address you used.
A credential supplied for a session lives in memory for that session. That is how the software is built, not a retention policy.
A credential you choose to keep is encrypted at rest. The key is made for that purpose alone. The file is written in one step, with owner-only permissions, and listed by name. The console shows you that it exists, and never what it is.
The warehouse connectors hold no write method at all. A read-only credential is everything TabTotal ever needs. The product sees what your own role sees, and no more.
You sign in to Tableau with your own token. Your own permissions apply, and the product reads what you can read.
Most of a hosted-service questionnaire does not apply to software running inside your own network. Pick the column you are reviewing.
Boreon runs the service on infrastructure it operates for you, and is the processor for what you put in it.
The same software runs inside your own network. Your organisation holds the admin account, and your content never reaches us. Most of a hosted-service questionnaire does not apply.
Every application produces its complete result on its own deterministic engine. The strongest sovereignty statement here is therefore not a residency clause: you can leave the assistant switched off and lose nothing.
The sub-processor list and the data processing summary are the two a review usually needs first.
If a question here is unanswered, ask us and we will answer it rather than route you to a form.