Where your data lives, and who can read it
Self-hosted software makes most security questions simple to answer and one of them harder. Both halves are on this page, including what happens if you lose the encryption key.
Bosun runs on a server you control, and all of its data lives in one SQLite file on that machine. Every credential you enter - your AI provider key, WhatsApp tokens, SMTP password, Google connection - is encrypted with AES-256-GCM using a key held only on your server, and is masked everywhere it is displayed. We have no account, no login and no copy of your data, which also means we cannot recover it for you.
- Where data lives
- One file, your server, your country
- Credential encryption
- AES-256-GCM
- Our access
- None
- Our copy
- None
- Recovery by us
- Impossible - back it up yourself
The measures, specifically
Data on your machine
One SQLite file on the server you chose, in the country you chose. Nothing is replicated to us.
Encrypted credentials
AES-256-GCM, with the key on your server only. Masked in the admin, the API and the logs.
Identity by phone number
Checked against your roster in code before anything is generated. Unknown numbers are refused before anything is stored.
Permissions in code
A message claiming to be the owner is not the owner. That attack is one of the tests run before every release.
Full audit trail
Every change to every job, with who made it, from which surface, and when. Nothing is deleted.
Official WhatsApp API
Meta's Cloud API, not an unofficial library, so your business number is never at risk from how we connect.
Your own provider accounts
Your AI key is billed to you directly. Your business's messages never pass through an account of ours.
Verified backups
A one-command backup that takes the database and its key together, and a restore that checks integrity before declaring success.
No analytics calling home
The product reports nothing to us. There is no usage telemetry to switch off, because there is none.
Your responsibility
- Server patching
- You
- Backups
- You - script supplied
- Keeping the key safe
- You
- Who has dashboard access
- You
- Recovery if all copies lost
- Nobody
We cannot rescue you
Self-hosting means the honest answer to "can you get my data back?" is no. There is no copy on our side to restore from, and the credentials are encrypted with a key we have never seen. That is the same property that makes the security answers simple, and it cuts both ways.
So two specific things are your responsibility, and they are worth reading twice. The encrypted database and its key must be backed up together - either one alone leaves the credentials unrecoverable. And a restore must remove the database's stale write-ahead log; ours does, and it verifies the result, because getting that wrong silently corrupts the file.
- Back up the database file and the key file together, in the same archive
- Keep that archive somewhere other than the server it came from
- Use the supplied backup script rather than copying the file while it is running
- The restore removes the stale write-ahead log and runs an integrity check - do not skip it
- Test a restore once, before you need one. It takes ten minutes
Who sees what
- Your server
- Everything
- Your AI provider
- Message text sent to it
- Meta / WhatsApp
- The messages, as always
- Us
- Nothing
- Us, during setup
- Only what you show us
What leaves your server
One thing does leave your machine, and you should know exactly what. To interpret a staff message, the text of that message and the relevant part of your procedures are sent to the AI provider whose key you configured - your own OpenAI or Anthropic account.
That means your provider's terms apply to that text, under your own commercial agreement with them rather than ours. For most businesses this is unremarkable. For a clinic or anyone handling regulated information it is the thing to assess, and the practical mitigation is to keep identifiers out of messages in the first place.
- Sent: the message text and the relevant procedure extract
- Sent to: your own AI provider account, on your key
- Not sent: your job history, your roster, your credentials
- Never sent to us - we are not in the path at all
- Read your provider's data retention terms before rolling out in a regulated setting
Instead, verifiable
- Source code
- Yours to read
- Test suites
- Included, runnable
- Where data sits
- Your machine
- What we can access
- Nothing
- Questions from your DPO
- Answered directly
What we do not have
Security pages usually list certifications. This one lists the ones we do not hold, because a buyer discovering that later is worse for everybody than reading it now.
If your procurement process requires any of these, we will fail it, and you should know that before spending time on a demo rather than after.
- No SOC 2, ISO 27001 or equivalent audit - none has been carried out
- No third-party penetration test report
- No signed uptime commitment, because we do not run your server
- No cyber insurance certificate to provide
- No data processing agreement covering data we hold, because we hold none
If you find a vulnerability
Email it. There is no bug bounty and no formal programme, but a security report gets read the day it arrives and answered whether or not it turns out to be valid.
If a vulnerability affects installations already sold, buyers are told directly with what to do about it, rather than having a patch released quietly.
- Report to the address on the contact page, marked security
- Acknowledged within one working day
- Affected buyers are notified directly, not left to notice a patch
- Please do not test against another buyer's installation - there is no shared infrastructure to test against anyway
On this page
Are you GDPR compliant?
Compliance is a property of a whole setup rather than a badge software carries. What we can tell you is what matters for your assessment: your data is on a server you chose, in a country you chose; we are not a processor because we receive none of it; and the one external flow is the message text going to your own AI provider under your agreement with them. Your data protection officer will get straight answers from us, including where the answer is unhelpful.
Who at your end can access my installation?
Nobody, unless you give somebody access - which some buyers do during setup and then revoke. There is no standing access, no support backdoor and no account on our side.
Is WhatsApp secure enough for this?
WhatsApp messages are encrypted in transit, and Bosun uses Meta's official Business API. It is still a consumer messaging app on staff phones, so the sensible discipline is to keep identifiers and confidential detail out of messages. For a clinic, that discipline is the actual safeguard - see the <a href="/solutions/clinic-task-management/">clinics page</a>.
What if I lose the encryption key?
Your jobs, people and messages are still readable - they are not encrypted with it. The stored credentials are not, so you re-enter them. Annoying, not fatal. The backup script takes the key alongside the database so this does not arise.
Can I run it with no internet access?
No. It needs to reach WhatsApp and your AI provider. An air-gapped installation is not possible with the current design, and we would rather say so than talk around it.