Chat met Jurre
SECURITY & COMPLIANCE

Security & Compliance at Boldcaster

Boldcaster holds what you wouldn't put anywhere else: your strategy, your numbers and how your people perform. That deserves a clear answer to the question of where it all goes.

SINCE JULY 2026

Our AI is European. The analysis of your business data runs at Mistral in France, call recordings run via tl;dv in Germany. No American AI touches your data.

Here's how we protect your data:

100% EU Hosted & GDPR Compliant

Your company data stays within the European Union. Databases (Supabase) and servers (AWS) are located exclusively in Frankfurt, Germany, so we comply with the GDPR. Our domain infrastructure runs via the Dutch provider TransIP, so we operate under Dutch law.

Two services run outside Europe, both without any substantive data: Calendly for scheduling a meeting and Stripe for payments. They see a name, an email address and a time, and nothing else. We'd rather be upfront about it than have you figure it out yourself.

European AI, not American

The AI that analyzes your strategy, numbers and team is Mistral, a French company that processes on servers in the EU. No American provider, no American parent company, and therefore no debate about the CLOUD Act. Call recordings run via tl;dv, a German company with storage in European data centers.

Training on your data is turned off, and that's a setting we can show you. Feel free to ask. Your business strategy, your numbers and your reviews are never used to train models.

Team member names never leave

The quarterly report looks at how your people perform. That's exactly the kind of information you don't just send out the door. So we replace names with a neutral label before anything goes to the AI, and only put them back in the app.

So the AI provider does see that someone is falling behind on their goals, but not who it is. In the app you simply see the name. This is safeguarded by a test that fails the moment a name ever slips through.

Enterprise-Grade Infrastructure

You don't have to be a corporate to get the best security. Boldcaster is built on Amazon Web Services (AWS), which means we ride on their ISO-27001 certified data centers. We also use Cloudflare as an impenetrable shield against DDoS attacks and malicious traffic. Via Coolify we manage our servers in isolation and securely.

Secure Access & Encryption

Access to the app is tightly secured via Google Cloud Single Sign-On (SSO). In addition, all communication between your browser and our servers (data in transit) and all data in the database (data at rest) is encrypted by default with the strongest industry standards (256-bit SSL/TLS).

Every environment stands on its own

Boldcaster runs on one platform with one database. Who can reach which data is not decided by the screen you see but by the database itself. Every table has row level security: a request for another organization's data simply returns nothing, even if someone bypasses the application.

The same applies to partners who use Boldcaster while advising their own clients. Such a partner administers the environments in their own portfolio and demonstrably reaches nothing else. Their clients cannot see each other, and the partner does not appear as a team member in their client's team. We verify this with a fixed set of tests that fails the moment a door is left open anywhere.

Questions?

Do you have specific questions for your IT manager? Get in touch via [email protected].