Skip to main content
BBossAI
SolutionsProductsCasesCompanyResourcesContact
Request Demo中文
Deployment & Compliance

Deployment, filing and data notice

This page explains BossAI's current hosting region, China ICP filing status, cloud data boundary, AI credential boundary, and future adjustment principles. Last updated: August 28, 2026.

Official websitebossaios.com
Authorization cloudcloud.destinykit.com
Primary deployment regionUnited States
Mainland China hosting/CDNNot currently used

1. Current architecture

The BossAI website and BossAI Cloud are currently hosted on infrastructure in the United States and are delivered over HTTPS. The five BossAI customer products may use cloud services, BossAI OS, controlled local software, or a combination depending on the product and enterprise deployment. BossAI Desktop is one currently documented controlled Windows delivery surface.

Cloud / server side: website, contact, customer, order, license, device, release, and necessary security/audit records.
Product and enterprise deployment: the processing location for tasks, projects, assets, professional files, and outputs depends on the enabled product and deployment model; AI credentials enter the approved BossAI OS / AI Gateway configuration boundary.

2. China ICP filing status

The website and authorization service do not currently use servers or CDN access nodes located in mainland China. Accordingly, the website does not display a mainland China ICP filing number at this time.

ICP filing obligations depend on the actual hosting provider, server and CDN region, application form, and service model. If BossAI later moves to mainland China infrastructure, uses mainland China CDN resources, or launches a mainland application, mini program, or other regulated internet information service, the filing and licensing position will be reassessed under the rules then in force.

This notice describes the current technical and operational setup. It is not legal advice and does not replace a determination by a competent authority or professional adviser.

3. Data stored in BossAI Cloud

  • Customer name, email address, and customer status;
  • Order reference, product, amount, currency, and payment status;
  • License plan, expiry, device limit, and validation state;
  • Device name, platform, app version, activation time, and last validation time;
  • Release records, download URL, SHA256, and release notes;
  • Administrative audit records and necessary server security logs.

License codes and device identifiers are handled as hashes in the cloud. A complete activation code is shown only once when it is issued.

4. Data ordinary Cloud records should not contain

  • Complete customer AI credentials;
  • Business secrets unrelated to customer, order, licensing, or support needs;
  • Complete professional project files or asset libraries unless required by the enabled product or explicitly submitted;
  • Full payment-card information;
  • Complete diagnostic packages unless the user submits them for support.

When a BossAI product or enterprise deployment invokes a third-party AI service, relevant inputs may be handled under that third party's rules. The actual data flow depends on the enabled product, configuration, and enterprise agreement.

5. AI credential and access boundary

BYOK is one optional enterprise deployment pattern supported by BossAI, not the only product model. If a customer uses its own AI credentials, raw credentials should be configured by an authorized administrator inside the approved BossAI OS / AI Gateway security boundary rather than distributed through business pages, projects, prompts, screenshots, or support requests.

  • BossAI does not sell underlying model credentials, Tokens, routing, or provider cost as the customer product;
  • Products and AI employees should invoke approved capability through the governed central AI Gateway;
  • Customers remain responsible for lawful authorization and internal governance of their own third-party accounts;
  • Inputs, outputs, professional judgment, and final business actions remain subject to the applicable customer's review responsibilities.

Possession of an invocation credential does not by itself establish a lawful basis for input materials, personal information, professional data, or other content.

6. Overseas storage and cross-border transfer

Because BossAI Cloud is currently hosted in the United States, the minimum account, order, license, and device information submitted to Cloud is transferred to and stored on servers outside mainland China. We process only the information needed for authorization, delivery, security, and support.

Businesses or teams using BossAI to handle personal information for other people are responsible for confirming a lawful basis and completing any notice, authorization, consent, or cross-border procedure required by applicable law.

7. Security and retention

  • Production traffic uses HTTPS;
  • The license signing private key remains on the cloud server, while Desktop contains only the public key;
  • Database access is controlled and the admin console requires a separate management token;
  • Important administrative actions are recorded in audit logs;
  • Data is retained only as long as needed to provide the service, evidence transactions, resolve disputes, perform security audits, and meet applicable legal obligations.

When a license ends or a deletion request is accepted, data will be deleted or anonymized where this does not conflict with transaction evidence, accounting records, security records, or other legal duties.

8. Access, correction, and deletion

You may request access to, correction of, or deletion of Cloud data associated with you, or ask about hosting, filing, and data storage:

BossAI Data and Compliance Request Form

We may ask for order, license, or email verification before disclosing or deleting data.

9. Changes

We will update this page and the privacy policy if the hosting region, data scope, filing status, or product architecture materially changes.

10. Regulatory references

These official Chinese-language sources are provided for general reference. Applicability depends on the actual service and guidance from the competent authority.

  • Measures for the Administration of Filing of Non-commercial Internet Information Services
  • Personal Information Protection Law of the People’s Republic of China
  • CAC Q&A on cross-border data flow provisions
BossAI · Enterprise AI Work Systems
About · Solutions · Products · Demo · Cases · Contact Us
Company · Pilot Program · ROI · Security · Resources: Pricing · Product Access · Resource Center · AI Access Boundary · Responsible AI · Changelog
Legal: Privacy · Terms · Refunds · Accessibility · 中文
© 2026 Daxinglian Cross-Border E-Commerce Co., Ltd.