Real conversation. Real protection.
See exactly how Boundary classifies every field in real time, protecting personal data while preserving full AI utility.
A real conversation, protected step by step
Employee connects CRM to ChatGPT
Sarah in sales connects HubSpot to ChatGPT via Boundary. She wants to draft follow-up emails using real client data.
Boundary provisions the connection through MCP. No browser extension. No copy-paste.
ChatGPT requests contact data
Sarah asks ChatGPT to draft a follow-up for her top deal. ChatGPT requests the contact record from HubSpot via the MCP tool call.
Boundary intercepts and classifies
Before the data leaves your infrastructure, Boundary evaluates every field individually against the schema profile for HubSpot contacts.
contact_name: PII (Tier 3). email: PII (Tier 3). deal_value: Analytical (Tier 1). company_name: Reference (Tier 2).
Sensitive fields are tokenised
PII fields are replaced with reversible reference codes. Analytical fields pass through unchanged. The AI receives a complete, usable record with zero personal data.
Sarah Mitchell becomes [Contact #7]. [email protected] becomes [withheld]. The deal value and company context pass through.
ChatGPT drafts the email
The model writes a contextually rich follow-up using real deal data, company context, and conversation history. The output is accurate and useful.
The draft references the correct deal value, timeline, and company. It does not contain any personal data because it never received any.
Boundary logs everything
The full interaction is recorded: which fields were requested, how each was classified, what was tokenised, and what was passed through.
Compliance teams can query the audit trail by user, tool, system, or time range.
Interface preview
Three tiers. Field-level precision.
Five layers. Zero gaps.
Schema classification
Livefield: emailBoundary learns the structure of each connected system. Field names, types, and relationships are mapped automatically.
Heuristic analysis
Livetier 3: personalEvery field is classified into one of three tiers using name heuristics, data sampling, and configurable rules.
Value inspection
Livevalue: email addressPII fields are replaced with reversible reference codes. Codes are user-scoped with a 7-day expiry, renewed on access.
Entity recognition
Liveentity: personPersonal identifiers embedded in free-text fields are recognised and protected. A name inside a notes field is tokenised like any other PII.
Policy outcome
LiveWithheldRole-based policies determine which users can access which tiers, per tool, per system. Configurable by IT.
What happens when someone leaves?
Sarah joins the company
IT provisions her Boundary access. She connects ChatGPT to HubSpot, Outlook, and Slack via MCP.
Hundreds of interactions
Sarah’s ChatGPT history contains hundreds of conversations. But it holds zero personal data. Every customer name is [Contact #7], every deal is [Deal #1].
Sarah is offboarded
Admin revokes her Boundary access in one click. OAuth tokens invalidated. The portal returns “expired” for every reference link.
Reference codes expire
Even if someone gained access to Sarah’s ChatGPT account, the conversation history contains only dead codes that resolve to nothing.
Sarah’s ChatGPT history contains every customer name, email, phone number, and deal detail she ever queried. That data persists indefinitely. You cannot revoke it.
Sarah’s ChatGPT history contains only reference codes and analytics. When her access is revoked, the codes die. Zero personal data to exfiltrate.
Interface preview
One policy. Every AI assistant.
- One security policy applies everywhere
- One audit trail captures everything
- One admin dashboard shows it all
See it in action
Book a demo to see how Boundary protects your data in real time.
Book a Demo