Boson

Security

How Boson approaches agent access, data boundaries, and operational security.

Outbound by default

The Boson agent connects out to the control plane over WebSocket. We do not require inbound SSH from Boson to operate a paired server.

Credentials

Join tokens are short-lived and used to pair an agent. Long-lived agent credentials can be revoked from the dashboard. Protect tokens like secrets.

Data boundaries

Application images and primary runtime data stay on your VPS. The control plane stores account, workspace, deploy metadata, and the observability data you enable.

Transport

Control-plane traffic uses TLS. Prefer keeping your gateway and agent on current releases.

Reporting issues

If you believe you have found a vulnerability, email security@getboson.com.