Legal / 06
Security
Last updated · August 16, 2026
This page describes the security practices Subject XYZ LLC applies to Boxic today. Boxic is an early-stage product in beta. We describe what we do — we make no certification, audit, or regulatory compliance claims.
Access control
- Every request is authenticated; project data is scoped to project and workspace membership at the database level.
- Private projects are not readable by anyone outside their member list.
- Publishing a project exposes only the curated public projection — team chat, reviews, invites, and internal history stay internal.
- Administrative access to production data is limited to the people who operate the service.
Data protection
- Traffic is encrypted in transit with TLS. Data at rest is encrypted by our infrastructure providers.
- Uploaded files are stored in a private bucket and served through short-lived signed links.
- Third-party credentials for optional connectors are stored encrypted and are never returned to the browser.
AI features
Boxie sends the prompt and the project context needed to answer it to a third-party AI provider through our gateway. That content is not used to train the provider's models. Boxie's answers can be wrong — verify anything you rely on for manufacturing.
Reporting a vulnerability
Email hello@boxic.io with steps to reproduce and what you were able to access. Please give us a reasonable window to fix the issue before disclosing it, avoid accessing other people's data, and don't run denial-of-service or spam tests. We will not pursue legal action against good-faith research that follows these guidelines.
Abuse and infringing content
To report public content rather than a vulnerability, use the content report form.