Trust centre
Trust centre: every document a reviewer asks for, and its status
One place for the documents a buyer or procurement team needs before trusting BOOSTD, including the ones that do not exist yet, marked as missing rather than left out.
Prefer to talk it through? Book a strategy call
How to read this page
An index that includes what is missing
This is the list a procurement reviewer works through: security, privacy, the companies that process data for us, certifications, availability, how to report a problem, and what happens after an incident.
BOOSTD is in early access, so several of those documents do not exist yet. They are listed anyway, with a status, because the alternative is making you ask for each one to find out.
The documents
Every trust document and where it stands
Items marked not yet available are needed before the platform processes customer data. None of them is needed for this website, which is covered by the published policies.
| Dimension | What it covers | Status |
|---|---|---|
| Security overview | How the platform is built: tenant isolation, encryption, approvals, audit and rollback, and the state of each. | Published on the security page, awaiting legal review. |
| Privacy policy | What this website collects, why, who processes it and how to have it deleted. | Published for this website, awaiting legal review. Platform privacy terms are not written yet. |
| Cookie policy | Which cookies this website sets and how consent is collected. | Published. |
| Subprocessor list | The companies that would process customer data for the platform, such as hosting, email and model providers. | Not yet available. The providers are being evaluated, and none processes customer data today. |
| Data processing agreement | The contract that governs BOOSTD processing personal data on your behalf. | Not yet available. |
| Certifications and audits | Independent attestations such as SOC 2 or ISO 27001. | None held. SOC 2 readiness is planned; nothing will be listed here until an auditor has issued it. |
| Status and availability | Live service status and incident history. | Not yet available. There is no production service to report on. |
| Vulnerability disclosure | How to report a security issue, and what happens after you do. | Not yet available. Use the contact page until a dedicated address is published. |
| Incident transparency | How and when customers are told about an incident that affects them. | Not yet available. |
| Editorial and content standards | How content on this site is written, reviewed and corrected, and the claims we refuse to make. | Published: editorial policy, content review policy and our standards. |
Signals we will not fake
What you will find here, and what you will not
Most trust pages are built from borrowed signals. These are the ones BOOSTD will only show once they are real, and the ones it will never show at all.
Shown only once real
- A certification badge, with the auditor and the report scope named
- Customer names or logos, with the customer’s written permission
- Testimonials from real customers, approved by them
- Availability figures, measured on the live service and linked to history
Never shown
- A hosting provider’s certification presented as BOOSTD’s own
- Counts of customers, pages or results that cannot be traced
- Logos of companies we have not worked with
- Results from a demo or simulated account presented as a customer’s
Accountability in the product
Where trust lives in the product itself
Documents describe a system. These are the parts of the system a customer would actually use to check it.
A published line between automatic and approved
What BOOSTD may do on its own is limited to reversible, low-risk work. Anything that changes what you say, spend or promise waits for a person.
Connection status you can see
Each integration shows its permissions, its status and when it last worked, so a broken or over-broad connection is visible rather than silent.
History you can reverse
Every change is recorded with what it was before and why it was made, and can be undone in one step. Rollback is meant to be easy to find under stress, not buried in settings.
Questions
Questions reviewers usually send us
Can I get a data processing agreement?
Not yet. A data processing agreement will be written and reviewed by counsel before the platform processes any customer data, because that is the point at which BOOSTD becomes your processor.
If you need one for a current engagement, ask through the contact page and we will tell you what is available for that engagement.
Why are so many items marked as not available?
Because the platform is in early access and has no production service yet. A status page with nothing to report, or a subprocessor list for a service that is not running, would be decoration.
Each item is listed now so you can see what will exist, and so that its absence is visible rather than discovered later.
Where do I report a security problem?
A dedicated disclosure address and policy have not been published yet. Until they are, use the contact page and say it is a security report; a person reads every message.
Need something that is not on this list?
Tell us what your review requires. If it exists we will send it; if it does not, we will say so and tell you whether it is planned.
Last updated · Not yet approved for publication