Trust Center
Security and data handling for hardware teams.
BootIntel processes sensitive device logs. This page summarizes how the platform handles submitted data, what is stored, which providers are used, and which controls are currently available.
Data Handling
- +Boot logs are processed to generate device fingerprints, findings, CVE matches, reports, and evidence exports.
- +Anonymous terminal previews are processed for analysis and are not saved to a fleet unless the user signs in and saves the log.
- +Saved scan retention follows the active plan: Free 30 days, Researcher 1 year, Pro 1 year, Business 3 years, Scale 5 years, Enterprise custom.
- +Opt-in research sharing is separate from normal analysis and must be explicitly selected.
Application Security
- +HTTPS is required for production traffic and the Cloudflare tunnel terminates public ingress.
- +Authentication uses magic link, OAuth, or mobile bearer sessions; passwords are not stored.
- +Session cookies are HttpOnly and production-secure, with CSRF origin checks on cookie-authenticated mutations.
- +Admin changes are audited, and admin self-lockout and last-admin removal are blocked.
AI Processing
- +AI reports are available on Pro and higher tiers and are generated only for scans the user owns.
- +If the AI provider is unavailable or not configured in production, AI analysis fails closed instead of returning mock output.
- +Boot logs submitted for AI analysis are sent to the configured provider API solely to generate the requested analysis.
- +BootIntel does not use submitted device data to train its own models.
- +Air-gap mode is a per-account toggle that disables all external AI processing. When enabled, boot log data never leaves the BootIntel API for an external AI/LLM provider. Available on request for regulated-industry accounts (medical, industrial OT, defense).
Procurement Notes
- +Zenofex LLC operates BootIntel from the United States.
- +Payment processing is handled by Stripe; BootIntel does not store full card details.
- +Private deployment, custom retention, SSO/SAML, and custom SLA terms are sales-led Enterprise options.
- +Security, legal, and privacy inquiries can be directed to [email protected], [email protected], or [email protected].
Subprocessors
Stripe
Payment processing and subscription management
Resend
Transactional email delivery
Google OAuth
Optional sign-in provider
OpenAI API
Optional AI analysis provider when enabled
Cloudflare
DNS, tunnel ingress, edge protection, and Web Analytics
Google Analytics 4
Aggregate site traffic measurement (no logged-in user data)
Google Firebase Cloud Messaging
Mobile push notifications to the BootIntel app