Security
How Boson approaches agent access, data boundaries, and operational security.
Outbound by default
The Boson agent connects out to the control plane over WebSocket. We do not require inbound SSH from Boson to operate a paired server.
Credentials
Join tokens are short-lived and used to pair an agent. Long-lived agent credentials can be revoked from the dashboard. Protect tokens like secrets.
Data boundaries
Application images and primary runtime data stay on your VPS. The control plane stores account, workspace, deploy metadata, and the observability data you enable.
Transport
Control-plane traffic uses TLS. Prefer keeping your gateway and agent on current releases.
Reporting issues
If you believe you have found a vulnerability, email security@getboson.com.