> For the complete documentation index, see [llms.txt](https://boundaryai.gitbook.io/boundaryai-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://boundaryai.gitbook.io/boundaryai-docs/help/security-and-compliance.md).

# Security & compliance

How BAI Analytics protects your data.

BAI Analytics follows industry-leading security practices to keep your feedback data safe:

* **Hosted on Google Cloud in the European Union**: production runs in the Paris region, so your data stays in the EU.
* **Data encryption** in transit (TLS 1.2 or higher) and at rest.
* **Two-factor authentication (2FA)** for all accounts, plus single sign-on and SCIM 2.0 user provisioning through your own identity provider for enterprise organisations.
* **Strict access controls** to protect your data.
* **PII redaction** at ingest, so personal information can be removed from feedback before it is ever stored (see [PII redaction](/boundaryai-docs/account-and-administration/updating-settings.md#pii-redaction)).
* **External penetration testing** to find and fix vulnerabilities.
* **Ongoing compliance monitoring by Vanta**.

## SOC 2

BAI Analytics runs a SOC 2 programme audited by Prescient Security. A **SOC 2 Type 1 report** is available on request, and the **SOC 2 Type 2** audit is in progress.

## Request a compliance report

We can share our SOC 2 report and a **real-time security and compliance report** on request. Contact **<info@boundary-ai.com>** or your BAI Analytics representative.

## Control access within your workspace

You also control who can see and do what inside BAI Analytics:

* **Organisation roles**: Admin, Member, and Viewer set what each person can do across the workspace.
* **AI assistant access**: an admin decides whether members can connect AI assistants; each connection is read-only and approved by the member who owns it.

See [Settings](/boundaryai-docs/account-and-administration/updating-settings.md) for managing members and roles.
