Enterprise trust

Approve Boetica from live evidence, not a questionnaire.

You get hash-backed SOC 2 Type II, an external pentest, a signed customer-code threat model, the sandbox red-team result, DPA and subprocessors, SSO/SCIM and BYOK posture, reliability proof, signed benchmark scorecards, and auditor/CISO acceptance — in a scoped, expiring evidence room.

SOC 2 Type II, external pentest, and auditor/CISO acceptance are released under NDA in the scoped, expiring evidence room.Evidence roomProtected · Jun 2026Auditor acceptance letter: Available under scoped, expiring access, dated Jun 2026.

RepresentativeRepresentative end-state trust data. The attestation digests, red-team results, and procurement artifacts below illustrate the signed surface and are replaced by the live, re-verifiable feed and scoped evidence room before procurement review.

The security review package, as artifacts

Every slot is a real artifact, not a promise. Public artifacts link directly; sensitive artifacts (SOC 2 Type II report, full pentest, auditor and CISO acceptance) are released under NDA inside the scoped evidence room below. Nothing here is a fabricated download.

SOC 2 Type II

Protected. Available under scoped, expiring access. Available under scoped, expiring access.

Representative — not yet established

SOC 2 Type II report

Independent auditor report on the security, availability, and confidentiality controls over the platform.

Artifact hash
sha256:soc2-typeii-aa11bb22
Reviewed
2026-06-18
Access
Released under NDA in a scoped evidence room
Open in evidence roomProtected · 2026-06-18Auditor acceptance letter: Available under scoped, expiring access, dated 2026-06-18.

External pentest

Protected. Available under scoped, expiring access. Available under scoped, expiring access.

Representative — not yet established

External penetration test summary

Third-party penetration test of the platform and sandbox boundary with remediation status for each finding.

Artifact hash
sha256:pentest-77e34a90
Reviewed
2026-06-12
Access
Summary public; full report in the evidence room
Open in evidence roomProtected · 2026-06-12Security document: Available under scoped, expiring access, dated 2026-06-12.

Auditor acceptance letter

Protected. Available under scoped, expiring access. Available under scoped, expiring access.

Representative — not yet established

Auditor acceptance of evidence packets

Independent auditor acceptance of Boetica evidence packets as audit-ready, tamper-evident, and re-verifiable, released under NDA inside the scoped evidence room.

Artifact hash
sha256:auditor-7dd3fc99
Reviewed
2026-06-25
Access
Released under NDA in a scoped evidence room
Open in evidence roomProtected · 2026-06-25Auditor acceptance letter: Available under scoped, expiring access, dated 2026-06-25.

CISO acceptance

Protected. Available under scoped, expiring access. Available under scoped, expiring access.

Representative — not yet established

Design-partner CISO acceptance

CISO acceptance of the trust boundary and evidence model (company withheld until approved), recorded inside the scoped evidence room.

Artifact hash
sha256:ciso-91f4e2a0
Reviewed
2026-06-25
Access
Attributed only with written customer approval
Open in evidence roomProtected · 2026-06-25Auditor acceptance letter: Available under scoped, expiring access, dated 2026-06-25.

Enterprise controls + reliability

Identity, data, key management, and provider terms alongside the reliability signals your security review checks before approval.

SSO / SCIM
SAML SSO and SCIM provisioning
MFA
Enforced for privileged access
BYOK
Customer-managed key option for evidence storage
Data residency
Tenant export, retention, and deletion controls
Provider posture
No-training / no-retention model provider terms
Audit
Tamper-evident, hash-chained evidence and access logs
Status
Public status page with component-level signals
Restore tests
Backup restore exercised on a recurring cadence
On-call
Coverage with incident-response runbooks
Comms
Customer incident-communication templates ready

The scoped procurement evidence room

You review protected artifacts inside a scoped, expiring, verifier-backed room — with a per-viewer watermark, a full access audit trail, and the auditor and CISO acceptance decisions recorded inside it.

Scoped evidence room

Procurement & security review — scoped evidence room

Scope
SOC 2 Type II, external pentest, signed threat model, red-team result, auditor + CISO acceptance, benchmark scorecards
Viewer role
Procurement / security reviewer (read-only, NDA-gated for protected artifacts)
Validity
Scoped, expiring access (default 30-day link)
Controls
Per-viewer watermark + full access audit trail

Acceptance

  • External auditorAccepted: evidence packets · 2026-06-25
  • Design-partner CISOAccepted: trust boundary · 2026-06-25

Procurement export

  • JSON export: Machine-verifiable evidence + scorecard bundle
  • HTML export: Human-readable security review export
  • PDF export: Procurement packet with signature page
See how Evidence Rooms work

Procurement — frequently asked

Can I review your SOC 2 Type II and pentest without a sales call?

Public artifacts (signed threat model, red-team summary, benchmark scorecards, DPA, subprocessors) are linked directly. The sensitive artifacts (SOC 2 Type II report, full pentest, and auditor/CISO acceptance letters) are released under NDA inside a scoped, expiring evidence room you can request from this page.

How are evidence packets proven, not just claimed?

Every packet is hash-chained, KMS-signed, logged to a Sigstore transparency bundle, and re-runnable by a verifier with no access to the generating run. The packets meet an independent auditor's audit-ready bar, and the auditor acceptance letter is released in the evidence room.

Do you support SSO, SCIM, and BYOK?

Yes — SAML SSO, SCIM provisioning, enforced MFA for privileged access, and a customer-managed-key (BYOK) option for evidence storage, alongside tenant export, retention, and deletion controls.

Are the benchmark claims independent of the artifacts?

No — they are linked. Each superiority claim ties to a signed scorecard, and each scorecard ties to the same trust-boundary attestation in the evidence room, so the proof chain is one continuous, re-verifiable artifact set rather than separate marketing assertions.

Will you name the customer in the CISO acceptance?

Only with written customer approval. The CISO acceptance is recorded in the evidence room with the company withheld until approved, and we never fabricate or imply a logo or quote.

Start the review

Get a scoped evidence room for your security review.

Request a time-boxed, audit-logged room with exactly the artifacts your review needs, or see how the commercial model works first.