TRUST

Security at Boxsy

Last updated July 2026. How we protect customer data on the Boxsy platform.

Boxsy is committed to protecting customer data.

1. Infrastructure

  • Hosted on reputable cloud infrastructure providers
  • Data encrypted in transit (HTTPS/TLS)
  • Access-controlled production environments

2. Access Controls

  • Role-based access controls
  • Limited employee access to production systems
  • Formal onboarding and offboarding procedures for employee access
  • Authentication safeguards

3. Data Handling

  • Logical separation of customer environments
  • Secure API integrations
  • Encrypted data transfer

4. Certifications & Independent Assessments

Boxsy has completed Google's Cloud Application Security Assessment (CASA) at Assurance Level AL1 (formerly known as Tier 2; Lab Tested – Lab Verified) for our Google Calendar and Gmail integrations. This third-party assessment, administered under the App Defense Alliance, evaluates application security controls against the OWASP Application Security Verification Standard (ASVS), covering authentication, session management, access control, communications, data validation, and configuration.

  • Assessment scope: Google Calendar (read-only, events) and Gmail (read-only) integrations
  • Assessed by: TAC Security, an independent third-party lab authorized by the App Defense Alliance
  • Certification ID: 3a7c166a
  • Issued: July 28, 2026
  • Valid through: July 29, 2027 (CASA requires annual revalidation)
  • Boxsy's use of these Google scopes has also passed Google's own OAuth App Verification review.

Boxsy is also currently working toward SOC 2 readiness, with formal audit preparation underway.

5. Vendor Management

We use vetted third-party providers for:

  • Cloud hosting
  • Payment processing
  • Analytics
  • AI model infrastructure

We review vendor security practices where appropriate.

6. Monitoring & Incident Response

  • Logging and monitoring of system activity
  • Security event review
  • Incident response procedures

If a material data breach occurs, we will notify affected customers in accordance with applicable law.

7. AI Security

  • Prompts processed securely
  • No public model training using customer data
  • Usage monitoring for abuse prevention

8. Customer Responsibilities

Customers are responsible for:

  • Protecting login credentials
  • Managing internal access permissions
  • Reviewing AI outputs before use

Google CASA Assurance Level AL1, assessed by TAC Security, an independent App Defense Alliance lab.

tac-security-esof-verified-and-secured-badge
RESPONSIBLE DISCLOSURE

Report a security issue.

If you discover a security vulnerability, please email security@boxsy.io instead of opening a public issue. We appreciate responsible disclosure and will work with you to resolve any concerns.