Security
Your trust is part of the product.
Boga will connect to accounts that matter to your business. We are building it with security and privacy as defaults, and we are honest about what is already in place and what arrives with launch.
How we protect Boga
Concrete practices, described without revealing details that would help an attacker.
Encryption in transit
Every page and form on tryboga.com is served over HTTPS with modern TLS and HSTS.
In place
Password hashing
Account passwords will be stored only as salted hashes using a modern, slow hashing algorithm — never in readable form.
When accounts launch
Encrypted tokens and backups
Social platform tokens will be encrypted at rest. Database backups are encrypted before they leave our server.
When integrations launch
Least-privilege access
Production access is limited to the people who need it, uses SSH keys only and is kept separate from development environments.
In place
Rate limits and abuse prevention
Public forms are validated on the server, size-limited and rate-limited, with spam protection that doesn’t get in your way.
In place
Dependency patching
We keep the operating system and application dependencies patched, and review dependency vulnerability reports.
In place
Careful logging
Our logs and monitoring are designed to exclude passwords, tokens, cookies and form contents.
In place
Backups and restore testing
Regular encrypted backups, with restores tested — because a backup only counts once it has been restored.
In place
Boga does not currently hold security certifications such as SOC 2 or ISO 27001. We will only say we do once an independent audit has confirmed it. Boga will never ask for your social media passwords — connections use each platform’s official authorization.
Responsible disclosure
Found a vulnerability? Tell us.
We welcome reports from security researchers and anyone who spots something that looks wrong.
What to include
- A description of the issue and where you found it.
- Steps to reproduce it, and any proof-of-concept.
- The impact you think it could have.
- How we can reach you for follow-up questions.
Please don’t
- Access, change or delete data that isn’t yours — use your own test data only.
- Run denial-of-service, load or spam tests.
- Use social engineering, phishing or physical attacks against our team or customers.
- Share the issue publicly before we’ve had a reasonable chance to fix it.
Our commitment
We will acknowledge your report within 5 business days, keep you updated as we investigate and let you know when it’s fixed. If you act in good faith and follow these guidelines, we will not pursue legal action against you for your research, and we will be happy to credit you if you wish.
See also our Privacy Policy and Acceptable Use Policy.