Skip to content
How It Works

Real conversation. Real protection.

See exactly how Boundary classifies every field in real time, protecting personal data while preserving full AI utility.

Pipeline view
Request pipeline
AI assistant
ChatGPT
Claude

> draft a follow-up for my top deal

AI client
MCP-compatible client

tool request: contact record lookup (CRM)

Boundary
Schema classification
Heuristic analysis
Value inspection
Entity recognition
Policy outcome
[Contact #7][Deal #1]
approved context
approved context
Model
Model
audit: classified 8 fieldsAllowed3Tokenised3Withheld2
A request enters, five classification layers act on every field, and only approved context reaches the model.
The Conversation

A real conversation, protected step by step

1

Employee connects CRM to ChatGPT

Sarah in sales connects HubSpot to ChatGPT via Boundary. She wants to draft follow-up emails using real client data.

Boundary provisions the connection through MCP. No browser extension. No copy-paste.

2

ChatGPT requests contact data

Sarah asks ChatGPT to draft a follow-up for her top deal. ChatGPT requests the contact record from HubSpot via the MCP tool call.

3

Boundary intercepts and classifies

Before the data leaves your infrastructure, Boundary evaluates every field individually against the schema profile for HubSpot contacts.

contact_name: PII (Tier 3). email: PII (Tier 3). deal_value: Analytical (Tier 1). company_name: Reference (Tier 2).

4

Sensitive fields are tokenised

PII fields are replaced with reversible reference codes. Analytical fields pass through unchanged. The AI receives a complete, usable record with zero personal data.

Sarah Mitchell becomes [Contact #7]. [email protected] becomes [withheld]. The deal value and company context pass through.

5

ChatGPT drafts the email

The model writes a contextually rich follow-up using real deal data, company context, and conversation history. The output is accurate and useful.

The draft references the correct deal value, timeline, and company. It does not contain any personal data because it never received any.

6

Boundary logs everything

The full interaction is recorded: which fields were requested, how each was classified, what was tokenised, and what was passed through.

Compliance teams can query the audit trail by user, tool, system, or time range.

→The AI produced a better result because it had structured, contextual data instead of a messy copy-paste. And zero PII was exposed.

Interface preview

Classification

Three tiers. Field-level precision.

HubSpot
source: HubSpot CRM
deal_amount£45,000Allowed
deal_stageNegotiatingAllowed
close_date2026-04-15Allowed
contact_name[Contact #7]Tokenised
company_name[Company #3]Tokenised
emailwithheldWithheld
phonewithheldWithheld
notesDiscussed pricing with [Contact #12], CFOTokenised
every field classified before context reaches the model
The Pipeline

Five layers. Zero gaps.

1

Schema classification

Livefield: email

Boundary learns the structure of each connected system. Field names, types, and relationships are mapped automatically.

2

Heuristic analysis

Livetier 3: personal

Every field is classified into one of three tiers using name heuristics, data sampling, and configurable rules.

3

Value inspection

Livevalue: email address

PII fields are replaced with reversible reference codes. Codes are user-scoped with a 7-day expiry, renewed on access.

4

Entity recognition

Liveentity: person

Personal identifiers embedded in free-text fields are recognised and protected. A name inside a notes field is tokenised like any other PII.

5

Policy outcome

LiveWithheld

Role-based policies determine which users can access which tiers, per tool, per system. Configurable by IT.

One sample value descends the five layers and is withheld before it reaches the model.
All five classification layers are live in the current platform.
Offboarding

What happens when someone leaves?

Day 1

Sarah joins the company

IT provisions her Boundary access. She connects ChatGPT to HubSpot, Outlook, and Slack via MCP.

Day 30

Hundreds of interactions

Sarah’s ChatGPT history contains hundreds of conversations. But it holds zero personal data. Every customer name is [Contact #7], every deal is [Deal #1].

Day 91

Sarah is offboarded

Admin revokes her Boundary access in one click. OAuth tokens invalidated. The portal returns “expired” for every reference link.

Day 98

Reference codes expire

Even if someone gained access to Sarah’s ChatGPT account, the conversation history contains only dead codes that resolve to nothing.

Without Boundary

Sarah’s ChatGPT history contains every customer name, email, phone number, and deal detail she ever queried. That data persists indefinitely. You cannot revoke it.

With Boundary

Sarah’s ChatGPT history contains only reference codes and analytics. When her access is revoked, the codes die. Zero personal data to exfiltrate.

Interface preview

Cross-Platform

One policy. Every AI assistant.

ChatGPT
Claude
Microsoft Copilot
Any MCP-compatible
One policy enforced across every connected assistant.
  • One security policy applies everywhere
  • One audit trail captures everything
  • One admin dashboard shows it all
Get Started

See it in action

Book a demo to see how Boundary protects your data in real time.

Book a Demo