Security and trust at Boosthis
The short answer. Boosthis is operated by Veqtara Tech Company, a company registered in the Kingdom of Saudi Arabia under commercial registration number 7054832287. It holds no independent assurance report of any kind — no SOC 2, no ISO 27001, no third-party penetration test. Data is held in one location, United States, with no choice of region. 5 outside companies receive data, each named below. The toolkit installed in your application is documented field by field, and a general install of it sends nothing anywhere.
What Boosthis is
Boosthis measures how a developer's own project behaves while it runs — how long its pages and requests take, which queries are slow, what is failing — and shows those measurements back to the developer, along with the problems it finds in them. A toolkit runs inside the customer's application and reports to the hosted service; a dashboard, and an optional assistant, read what it reported.
That places Boosthis inside your application, which is why this page exists. The relevant questions are what that code does, what leaves your process, where it goes and who can read it. Each is answered below.
What the toolkit collects, and what it does not
The full answer is published field by field at /docs/what-boosthis-collects, generated from the kits' own disclosure record rather than written as marketing copy. The boundaries that matter to a reviewer:
- Your source code is never read. No kit opens, scans, indexes or uploads a source file, and no source text is stored on our servers.
- Request bodies, response bodies, query strings and headers are not collected and not uploaded.
- Crash reporting records a redacted code location and the error type, never a raw stack and never a value.
- A personal-data guard runs on the sending side, inside your process, and again on the receiving side. Both layers reject a batch on the first hit, so an out-of-date kit cannot bypass the guard by renaming a field.
- A general install — the toolkit with no project key — measures locally and sends nothing anywhere.
Which companies receive data
This is the whole list, generated from the same record the privacy policy renders. Boosthis sends each company the data named beside it for the purpose named beside it. This does not assert that each provider's contractual terms restrict its use to that purpose.
| Company | What it does | What reaches it | Where it is processed |
|---|---|---|---|
| Moyasar. | payments — embedded payment form and subscription charges. | card details sent directly from the browser through Moyasar's form embedded in Boosthis-hosted checkout (never to Boosthis's servers), the amount and currency of each charge, the billing name and email on the payment, and the reusable payment token that makes a renewal work. | Kingdom of Saudi Arabia. |
| Resend. | email delivery — the account emails listed under Account data. | your email address, the subject, and the body of the message. | United States. |
| OpenAI. | AI processing — answers from the Ask Boosthis assistant, and the scheduled rule-drafting pass. Two companies sit in this path: the call leaves Boosthis to an AI gateway operated by Replit, on Replit's own account and credential, and Replit passes it to OpenAI, which generates the answer. Replit is also the hosting recipient listed separately; on this path it is the intermediary, and what it can see is the call itself. | the screened question and the privacy-safe digest described in the assistant section, and — for drafting — aggregated privacy-safe signals; one short sentence a developer or their assistant wrote, where a promise or a submitted claim cannot be read by the plain word match and the account owns the project, sent once so it can be mapped onto one subject the project already measures — and, in the same call, the list it has to choose from: up to forty of that project's own subjects, each a route, problem, job or daily-reading label with the figures already measured for it, which is that project's own data and not pooled with anyone else's; separately, the text of our own rule book, which is ours rather than a customer's: rule titles, match conditions and detector patterns, plus the prescriptive fix text on the maintainer-side drafting and review calls that cannot work without it; the provider's published position for its API is that none of it is used to train AI models. | United States. Which country actually processes it is not confirmed; this is our best understanding, recorded as an understanding. |
| Replit. | hosting and the managed PostgreSQL database, and the AI gateway in front of OpenAI. | everything this document describes as stored: account data, telemetry, and the operational database as a whole. | United States. |
| Google Cloud. | backup storage — the routine encrypted database backups described under Retention. | a copy of the operational database, in a private bucket. | United States. |
Three destinations sit outside that list because the customer chose them rather than Boosthis: an alert webhook you configure, a chat workspace you connect, and an AI assistant you connect. Each receives what you point it at, under your own agreement with whoever operates it.
Notice before that list changes
Before another company starts receiving account data or telemetry, it is named on this page and in the privacy policy at least 14 days before it begins — unless a change has to be made sooner to keep the service running or secure, in which case it is named as soon as it takes effect. That is the period stated in the controlling terms, and this page renders the same number rather than a second copy of it.
A company named ahead shows two days beside it in the table: the day it was named, and the first day it may receive anything. No company in the table is named ahead of starting: none is waiting to receive data.
The promise above does not depend on you coming back to compare the table. Leave an address and you will be emailed when this list changes, and for nothing else.
Where data is held
- Where the service runs: the Boosthis servers and the database behind them run in the United States.
- Whether your data crosses a border: some of it does. Moyasar holds what reaches it in the Kingdom of Saudi Arabia; Resend, Replit and Google Cloud hold what reaches them in the United States; what reaches OpenAI leaves the Kingdom of Saudi Arabia too, but which country processes it is not confirmed.
These are two answers to two questions, and neither one implies the other. That the service runs in the United States does not mean nothing leaves it, and that something leaves it does not mean the service runs anywhere else.
One location, and no choice of region
There is one location and no choice of region. Boosthis does not offer a European, a North American or an in-Kingdom option at signup, and there is no plan on any date to add one. Every customer's data is held in the same place, and the places it is processed are: Kingdom of Saudi Arabia, United States.
Boosthis is one company operating one deployment from the Kingdom of Saudi Arabia. A second region is not a setting — it is a second database, a second backup regime, a second set of keys and a second place every future change has to be proven. Offering one before it can be operated properly would be worse for a buyer than not offering it.
If you need your data held somewhere else:
- If your requirement is that nothing leaves your own infrastructure, the toolkit can be installed without a project key. A general install measures your application and sends nothing anywhere — there is no account, no upload and no server side to it.
- If your requirement is a named region, Boosthis cannot meet it today. Say so before you buy rather than after: write to support@boosthis.com and you will get a direct answer about whether the requirement is met, not a roadmap.
- If your requirement is knowing when the answer changes, the notice below covers it. A change to where data is held is a change to the list of companies that receive it, and that list is what the notice is about.
Every company outside the Kingdom of Saudi Arabia is on that list because a part of the service cannot be provided without it. For each one, the ground relied on and the safeguards are recorded in the transfer register named under Documents.
Who inside Boosthis can see your data
Boosthis is operated by a small team. Access to the operational database and the admin surfaces is limited to the maintainer and to named admin members, each with a role that decides what they can reach; every admin session is separate from a customer session, expires, and is revoked immediately when a role changes or a member is disabled. Every change made from an admin surface is written to an audit log.
The dashboard's assistant and the scheduled rule-drafting pass send a screened question and a privacy-safe digest of numbers to the AI provider named in the table above. Free-form prose and anything identifier-shaped is removed before it leaves the server, and the answer is screened again before it is shown.
Reporting a vulnerability, and what happens next
Report privately by email to support@boosthis.com with "security" in the subject. The same address is published in machine-readable form at /.well-known/security.txt, generated from the server's own contact configuration rather than typed, so the two cannot drift apart. You do not need a Boosthis account to report one.
- Acknowledgement: within 5 business days.
- Progress: you are kept updated while it is being fixed.
- Disclosure: coordinated. The request is a window of 90 days from the initial report before details are published — shorter if a fix lands quickly, longer if the issue is unusually complex.
- Credit: given in the release notes, with your consent.
- Please do not file a public issue for a security report.
An incident affecting the service's availability is posted on the status page while it is open. An incident affecting personal data is notified to the affected customers and to the supervisory authority as the privacy policy sets out.
Independent assurance
This is the section a vendor questionnaire is really asking about, so it is answered plainly rather than left out.
SOC 2 Type II: not held
An auditor's report on whether stated security controls operated as described over a period, usually six to twelve months. It is the report most software buyers in North America ask for first.
Boosthis has never engaged an auditor, so no report exists and no audit is under way. The earliest a Type II report could exist is the end of an observation window that has not started.
ISO/IEC 27001: not held
A certification that an information security management system meets an international standard, issued by an accredited certification body after an audit.
Boosthis holds no ISO certification of any kind and has not applied for one. There is no management system documented to the standard, which is the work the certificate would attest to.
Independent penetration test: not held
A security firm attacking the running service under contract, and a report a buyer can read describing what it found and what was fixed.
No outside firm has been engaged to test this service, so there is no report to send. What testing exists is the maintainer's own, and the maintainer's own testing is not an independent test.
PCI DSS attestation: not held
The card industry's attestation, required of a service that stores, processes or transmits cardholder data.
Card details are entered on the payment provider's own pages and reach Boosthis's servers at no point, so the scope an attestation would cover does not sit here. The provider's own compliance is the provider's to state, and Boosthis does not state it on their behalf.
Whether Boosthis pursues an independent report, which one, what it would cost and what would change the answer is a written decision rather than an open question. It is recorded in the engineering decision records as independent-assurance-report, and the condition that triggers it is observable: the first prospective customer who declines to buy, in writing, because no report exists. Ask for a copy of that record by email if it is relevant to your review.
What exists instead
None of the following is independent, and none of it is a substitute for an auditor's opinion. It is listed because a reviewer who has just read four "not held" answers is entitled to know what does exist.
- A written vulnerability reporting policy, with the acknowledgement time and the disclosure window stated on this page.
- A maintained threat model covering the service's trust boundaries, its admin surfaces and its residual risks.
- A register of every outside company that receives data, with what reaches each one and where it is processed — the same record this page and the privacy policy are generated from.
- A register of every transfer outside the Kingdom of Saudi Arabia, recording the ground relied on and the safeguards, assembled for legal review.
- Automated checks that run on every change: a personal-data guard on both the sending and receiving side of telemetry, and a register of published claims that fails the build when a page promises something the code does not do.
- A public status page with the service's own health and its open incidents, and an uptime watcher that runs outside this service so an outage cannot silence its own measurement.
Documents
Everything a review normally asks for, and for each one whether it can be sent. A document that exists but is not published is named here with how to ask for it, rather than left off the page.
| Document | What is in it | Can you have it? |
|---|---|---|
| Data Processing Agreement. | The published agreement for customer application telemetry, incorporated into the Terms. | Published — In full at /processing. /processing |
| Companies that receive Boosthis data. | The separate recipient list and per-company processor and onward-transfer positions. | Published — In full at /subprocessors; email change notices are available on this page. /subprocessors |
| Vulnerability reporting policy. | Where to report a security problem, what happens next, the acknowledgement time, and what is in and out of scope. | Published — In full, in the section below. /trust#reporting |
| security.txt. | The machine-readable reporting address a scanner or a researcher's tooling looks for, generated from the server's own contact configuration rather than typed. | Published — At the address below. /.well-known/security.txt |
| Privacy policy. | What is collected, what is not collected, how long each thing is kept, who receives it, and every right a customer can exercise. | Published — At /privacy, with the controlling terms at /terms. /privacy |
| What the toolkit collects. | Field by field, what each kit measures inside a customer's own application and what it sends — generated from the kits' own disclosure record. | Published — At the address below. /docs/what-boosthis-collects |
| Service status and incidents. | The service's current health and its open incidents, plus an uptime measurement taken from outside the service. | Published — At the address below. /status |
| Threat model. | The service's trust boundaries, the attacker positions considered, the controls at each boundary, and the residual risks that remain. | Exists, sent on request — It is a working engineering document that names residual weaknesses and the exact controls standing in front of them, which is an inventory worth writing for a reviewer and not worth publishing to the open internet. Write to support@boosthis.com naming the document and the company you are reviewing for. It is sent by email to a named reviewer. |
| Cross-border transfer register. | Every transfer of data outside the Kingdom of Saudi Arabia, the ground relied on for each, the safeguards, and whether an in-Kingdom alternative exists. | Exists, sent on request — It is assembled for legal review and records questions that are still open, so publishing it would present an engineer's assembly as a settled legal position. Write to support@boosthis.com naming the document and the company you are reviewing for. It is sent by email to a named reviewer. |
| Data-protection obligation map. | Each provision of the Kingdom's Personal Data Protection Law and its Regulations, against what this codebase does about it. | Exists, not shared — It is an engineering assembly awaiting review by a lawyer qualified in Saudi data protection law. Every verdict in it is a statement about what the code does, never a finding that an obligation is discharged, and handing it to a buyer would read as a compliance opinion that nobody qualified has given. Boosthis does not claim to be certified against that law, and this document would not support the claim if it did. |
| Accessibility conformance report. | A statement of how the product measures against an accessibility standard, in the form a public-sector buyer asks for. | Does not exist — No conformance report has been produced. The product is tested against a written reading contract covering keyboard reach, focus order and text size, but that testing has not been assembled into a conformance report and is not one. |
What this page does not claim
Boosthis is not certified against any standard, has not been audited by anyone, and has not been tested by an outside security firm. Nothing above should be read as saying otherwise, and if you find a sentence on any Boosthis page that does, it is a mistake and we would like to hear about it at support@boosthis.com.