Enterprise
The controls your security team will ask for, already on.
Enterprise workspaces add identity from your directory, the admin split your auditors expect, an event stream into your SIEM, network and device restrictions, scanning and DLP on the way in and out, legal holds and retention rules, and the option of a transfer node in your own cloud account.
Plans: Everything on this page is included in the Enterprise plan; a few items (SSO, legal hold, auto-delivery) are also called out on the pricing page. Studio workspaces get watermarks, archive tiers, review and automations; Enterprise adds the controls below.

How it works
In order
- 01
Connect identity
OpenID Connect with PKCE to Okta, Microsoft Entra ID, Google Workspace, Keycloak or any OIDC provider, routed by email domain and optionally enforced. SCIM provisions members and groups from the directory and removes them the same way.
- 02
Split the admin role
Billing, members, security and content are separate scopes. Sessions and devices are visible and revocable; every admin action is in the audit log and in your SIEM within seconds.
- 03
Set the perimeter
An IP allow-list with a grace window that cannot lock you out, a device policy that limits transfers to enrolled computers, scanning and quarantine on arrival, a DLP check before any link goes out, and a legal hold that stops permanent deletion.
Everything in Enterprise
Shipped items are marked Live; the rest is committed roadmap or built and waiting on an outside approval, and says so.
- Live
Single sign-on
One OIDC provider per workspace, routed by email domain. Enforce it so password sign-in is refused for those domains; new people are created on first sign-in with a default role; your provider owns the second factor.
- Live
SCIM provisioning
Members and groups from Okta or Entra, created, updated and deactivated from the directory. Directory-managed accounts cannot be re-addressed outside the organisation.
- Live
Sessions and devices
Every sign-in with device, a hashed address hint, two-factor state and expiry; revoke one or sign out every other device. API keys cannot touch sessions.
- Live
Admin scopes
Billing, members, security and content as separate grants. The owner always has all four; without the feature every admin has all four.
- Live
Audit export and SIEM stream
CSV or JSON Lines of the audit log and workspace events (100,000 rows per export), and a signed HTTPS stream of events to one endpoint per workspace, resumable after a pause.
- Live
IP allow-list and device policy
Up to 200 addresses or ranges (IPv4 and IPv6), a 15-minute owner grace window after every change, and a test button. Require the desktop app for member transfers or restrict them to approved computers.
- Live
Scan on arrival and quarantine
Every arriving file is scanned for malware; hits are quarantined automatically and posted to your channel. Whether sharing is blocked while a scan is queued is a workspace decision.
- Live
DLP hooks
Before a link is created, Boita asks your DLP service and honours the answer. Your classifier, your rules.
- Live
Legal hold and hold exports
A hold stops anything in scope from being purged, whatever the retention setting, with the reason recorded. Export a hold as a package for counsel.
- Live
Forensic watermark
An invisible per-recipient mark on video deliveries and a "who leaked this?" tool that reads it back from a clip.
- Live
Archive tiers and retention rules
Move finished folders to cold storage with a manifest and restore on demand; retention rules per folder decide what is kept for how long.
- Live
Auto-delivery and a dedicated lane
Push anything that lands to your own S3-compatible bucket or transfer server, and run on a dedicated bandwidth lane on the transfer node with 100 or more parallel sessions.
- Live
Self-managed transfer nodes
Stand up a transfer node in your own AWS account with our Terraform module; the workspace, links and receipts stay with Boita. Regional nodes elsewhere on request.
- Live
Security questionnaire pack
A data processing agreement, sub-processor list and DPDP statement are published; the TPN control-by-control gap list and the 2026-09-21 security review are available on request. Counsel review of the legal pack and an independent penetration test are in progress.
The numbers
Real limits, stated up front.
Taken from the product’s configuration and plan data, not from a sales deck.
Can we keep files in our own cloud account?
Two ways. Auto-delivery pushes everything that lands to your own S3-compatible bucket or transfer server within minutes. A self-managed transfer node in your AWS account (Terraform module) keeps the storage under your account while Boita runs the workspace, links and receipts.
Where do you stand on SOC 2, ISO 27001 and TPN?
SOC 2 Type II is in progress on a compliance platform; ISO/IEC 27001 is targeted within 12 to 18 months of launch; the TPN self-assessment against the MPA content-security guidelines is written control by control and available on request with its gap list. Nothing is claimed as certified until it is.
Does the security team get an incident feed?
The SIEM stream carries every workspace event; status.boita.io announces incidents and maintenance; every incident gets a written post-mortem. The Trust page lists recovery objectives and the backup schedule.
Is there a data processing agreement?
Yes, published at /legal/dpa with the sub-processor list and the DPDP statement. Counsel review of the pack is in progress; custom terms are handled per contract.
Next step
Try it, or ask first.
Start free with 10 GB and no card, book a demo, or talk to a person on WhatsApp. Leads from this page reach us with the page name attached, so the reply already knows what you read.
Talk to us about an Enterprise workspace.
Send the questionnaire, or book a call; a person replies within two hours on Enterprise and the answers are already on the Trust page.