Open for new installations worldwide One-time price 1 year support included
Trust & security

Where your data lives, and who can read it

Self-hosted software makes most security questions simple to answer and one of them harder. Both halves are on this page, including what happens if you lose the encryption key.

Your server AES-256-GCM credentials No access for us
In short

Bosun runs on a server you control, and all of its data lives in one SQLite file on that machine. Every credential you enter - your AI provider key, WhatsApp tokens, SMTP password, Google connection - is encrypted with AES-256-GCM using a key held only on your server, and is masked everywhere it is displayed. We have no account, no login and no copy of your data, which also means we cannot recover it for you.

Where data lives
One file, your server, your country
Credential encryption
AES-256-GCM
Our access
None
Our copy
None
Recovery by us
Impossible - back it up yourself
What is in place

The measures, specifically

Data on your machine

One SQLite file on the server you chose, in the country you chose. Nothing is replicated to us.

Encrypted credentials

AES-256-GCM, with the key on your server only. Masked in the admin, the API and the logs.

Identity by phone number

Checked against your roster in code before anything is generated. Unknown numbers are refused before anything is stored.

Permissions in code

A message claiming to be the owner is not the owner. That attack is one of the tests run before every release.

Full audit trail

Every change to every job, with who made it, from which surface, and when. Nothing is deleted.

Official WhatsApp API

Meta's Cloud API, not an unofficial library, so your business number is never at risk from how we connect.

Your own provider accounts

Your AI key is billed to you directly. Your business's messages never pass through an account of ours.

Verified backups

A one-command backup that takes the database and its key together, and a restore that checks integrity before declaring success.

No analytics calling home

The product reports nothing to us. There is no usage telemetry to switch off, because there is none.

Your responsibility

Server patching
You
Backups
You - script supplied
Keeping the key safe
You
Who has dashboard access
You
Recovery if all copies lost
Nobody
The inconvenient half

We cannot rescue you

Self-hosting means the honest answer to "can you get my data back?" is no. There is no copy on our side to restore from, and the credentials are encrypted with a key we have never seen. That is the same property that makes the security answers simple, and it cuts both ways.

So two specific things are your responsibility, and they are worth reading twice. The encrypted database and its key must be backed up together - either one alone leaves the credentials unrecoverable. And a restore must remove the database's stale write-ahead log; ours does, and it verifies the result, because getting that wrong silently corrupts the file.

  • Back up the database file and the key file together, in the same archive
  • Keep that archive somewhere other than the server it came from
  • Use the supplied backup script rather than copying the file while it is running
  • The restore removes the stale write-ahead log and runs an integrity check - do not skip it
  • Test a restore once, before you need one. It takes ten minutes

Who sees what

Your server
Everything
Your AI provider
Message text sent to it
Meta / WhatsApp
The messages, as always
Us
Nothing
Us, during setup
Only what you show us
The AI provider question

What leaves your server

One thing does leave your machine, and you should know exactly what. To interpret a staff message, the text of that message and the relevant part of your procedures are sent to the AI provider whose key you configured - your own OpenAI or Anthropic account.

That means your provider's terms apply to that text, under your own commercial agreement with them rather than ours. For most businesses this is unremarkable. For a clinic or anyone handling regulated information it is the thing to assess, and the practical mitigation is to keep identifiers out of messages in the first place.

  • Sent: the message text and the relevant procedure extract
  • Sent to: your own AI provider account, on your key
  • Not sent: your job history, your roster, your credentials
  • Never sent to us - we are not in the path at all
  • Read your provider's data retention terms before rolling out in a regulated setting

Instead, verifiable

Source code
Yours to read
Test suites
Included, runnable
Where data sits
Your machine
What we can access
Nothing
Questions from your DPO
Answered directly
Not claimed

What we do not have

Security pages usually list certifications. This one lists the ones we do not hold, because a buyer discovering that later is worse for everybody than reading it now.

If your procurement process requires any of these, we will fail it, and you should know that before spending time on a demo rather than after.

  • No SOC 2, ISO 27001 or equivalent audit - none has been carried out
  • No third-party penetration test report
  • No signed uptime commitment, because we do not run your server
  • No cyber insurance certificate to provide
  • No data processing agreement covering data we hold, because we hold none
Reporting a problem

If you find a vulnerability

Email it. There is no bug bounty and no formal programme, but a security report gets read the day it arrives and answered whether or not it turns out to be valid.

If a vulnerability affects installations already sold, buyers are told directly with what to do about it, rather than having a patch released quietly.

  • Report to the address on the contact page, marked security
  • Acknowledged within one working day
  • Affected buyers are notified directly, not left to notice a patch
  • Please do not test against another buyer's installation - there is no shared infrastructure to test against anyway

On this page

Are you GDPR compliant?

Compliance is a property of a whole setup rather than a badge software carries. What we can tell you is what matters for your assessment: your data is on a server you chose, in a country you chose; we are not a processor because we receive none of it; and the one external flow is the message text going to your own AI provider under your agreement with them. Your data protection officer will get straight answers from us, including where the answer is unhelpful.

Who at your end can access my installation?

Nobody, unless you give somebody access - which some buyers do during setup and then revoke. There is no standing access, no support backdoor and no account on our side.

Is WhatsApp secure enough for this?

WhatsApp messages are encrypted in transit, and Bosun uses Meta's official Business API. It is still a consumer messaging app on staff phones, so the sensible discipline is to keep identifiers and confidential detail out of messages. For a clinic, that discipline is the actual safeguard - see the <a href="/solutions/clinic-task-management/">clinics page</a>.

What if I lose the encryption key?

Your jobs, people and messages are still readable - they are not encrypted with it. The stored credentials are not, so you re-enter them. Annoying, not fatal. The backup script takes the key alongside the database so this does not arise.

Can I run it with no internet access?

No. It needs to reach WhatsApp and your AI provider. An air-gapped installation is not possible with the current design, and we would rather say so than talk around it.

Ready when you are

Your brand. Your server. Your assistant.

Watch it read a real message and build the job list, before you spend anything.

WhatsApp Pricing Book a demo