Docs
How Borehole works inside
What runs where, what crosses from your repository, and the documents a security or legal review asks for. Each page states what the code does, and the numbers on it are read from the code.
Concepts
- Architecture
- What runs where in a public survey and in a private one, and what crosses between them.
- Keys and tokens
- A Report key is what you paid for. A collector token lets the collector act for your account. How the two differ.
Your code and data
- What happens to your code
- Everything the collector sends from a private repository, how to check it before it is sent, and what we still cannot prove.
- Run it in your own cloud
- The collector in a Confidential VM in your own Google Cloud project, with every command.
- Surveying a target
- How a buyer surveys a private target: the target runs the collector with the buyer's key and decides who reads the report.
- Attestation
- What a report records about where its survey ran, and how to check it without trusting us.
Legal and security
- Sub-processors
- Every service that receives data Borehole holds, and what each one gets.
- Data processing agreement
- The agreement under which we process personal data in a private survey, as your processor.
- Reporting a vulnerability
- How to report a vulnerability in borehole.dev or the collector.
- Terms
- The terms you accept when you buy or use Borehole.
- Privacy
- What we hold about you, why, for how long, and your rights.