
B.O.R.I.S
An infrastructure context layer for engineers. It connects AWS, GitHub and Slack, continuously maps what is really deployed, then serves that context to people in Slack and to AI agents over MCP, with data kept in your own AWS account.
What is B.O.R.I.S?
B.O.R.I.S is an infrastructure context layer built by Sirob Technologies, an Estonian company, for engineering teams that run cloud estates and AI agents side by side. The premise stated on the homepage is that AI agents lose the environment the moment a session ends: they reason from the repository and miss everything the code does not say. B.O.R.I.S connects to AWS, GitHub and Slack through customer-side IAM roles and OAuth, then continuously pre-computes a knowledge layer across those systems, resolving identities between them, tracking changes over time, and recording the decisions a team makes as work happens.
That layer is exposed through three named interfaces. A Slack assistant answers questions from people, with evidence drawn from the live environment. An MCP server serves the same context to coding agents such as Cursor, Claude Code and Codex, so a review agent running in CI reads exactly what the engineer's agent read, without per-agent wiring. An API lets internal systems consume it directly.
The published use cases fall into five families: grounded coding and review, production support, security questions spanning code and cloud, onboarding and knowledge continuity, and time and token savings. Worked examples show the tool naming the Valkey version actually deployed rather than the Redis the repository implies, tracing a latency alarm to a cache resize twenty-five minutes earlier, and surfacing why a service runs on Spot capacity from a decision recorded by an engineer who has since left the company.
Deployment is hybrid: data stays at rest in the customer's own AWS account rather than the vendor's. Access is read-only by default, write actions are explicit, and the vendor states that no third-party SaaS sits in the data path. A private cloud installation keeps all operations inside the customer's cloud, with options to bring your own encryption key and your own language model.
Pricing starts at 500 USD per month for 20 agent hours and rises to 1,000 USD for 40, with a custom tier in private beta, sold on a twelve-month subscription through AWS Marketplace.
What it does
- Answer questions about your live AWS estate directly in a Slack thread, with evidence attached
- Serve the same infrastructure context to Cursor, Claude Code and Codex over MCP, with no per-agent wiring
- Investigate incidents across cloud and code, tracing changes back to the commit that caused them
- Map service dependencies across accounts and environments, and build organisation-wide inventories
- Preserve team decisions and trade-offs so they survive the people who made them
- Give internal agents safe read-only access to production for troubleshooting, security checks and code review
- Run a cloud bill optimisation check and surface the cause of unexpected AWS spend
When to use B.O.R.I.S / When not to
A quick filter to help you decide if B.O.R.I.S is the right fit.
When to use B.O.R.I.S
- DevOps, platform and SRE teams running multi-account AWS estates
- Engineering teams whose coding agents (Cursor, Claude Code, Codex) keep guessing at production
- Organisations in regulated sectors — healthcare, fintech, govtech — that need data to stay in their own perimeter
- Teams where infrastructure knowledge sits in two or three people's heads
- Platform teams building their own internal AI agents that need safe, read-only production context
When not to use B.O.R.I.S
- Teams not on AWS today: Google Cloud, Azure and GitLab are still listed as coming soon and design-partner gated
- Teams that need Microsoft Teams or Discord natively, since only Slack is supported at present
- Small budgets, as entry costs 500 USD per month on a twelve-month subscription with no free plan
- Buyers who require a certification already in force, because SOC 2 Type I is only a target for H2 2026
- Anyone whose work does not touch cloud infrastructure, code repositories or engineering operations
How to use B.O.R.I.S
A typical end-to-end flow, from setup to results.
- Book a demo through the calendar link, or join the public Slack playground to try the assistant first
- Purchase through AWS Marketplace on a twelve-month subscription
- Connect your AWS organisation using customer-side IAM roles, with PrincipalOrgID protection for cross-account assumption
- Connect your GitHub organisation and your Slack workspace over OAuth
- Let B.O.R.I.S build the context layer, which it pre-computes and refreshes continuously across the connected systems
- Ask questions in Slack by tagging B.O.R.I.S in a thread and read the answer with its evidence
- Point Cursor, Claude Code or Codex at the MCP endpoint; the vendor states each coding agent is set up on install
- Wire the review agent in your CI pipeline to the same layer so it reads the same context
- Connect internal agents or systems through the API
- Move up to the Pro tier for scheduled and event-triggered workflows once the read-only usage is established
Pros & Cons
Pros
- Data stays at rest in the customer's own AWS account rather than with the vendor
- Read-only by default, with write actions made explicit
- One shared context for every agent, with no per-agent wiring to maintain
- A BAA is offered at every tier, with no seat minimums and no tier discrimination
- Concrete security engineering, including PrincipalOrgID confused-deputy protection
- Thirty-day money-back guarantee and purchase through AWS Marketplace
- Founding team with a stated decade of prior work on HIPAA-regulated infrastructure
Cons
- No privacy policy, no terms of service and no legal notice are published anywhere on the site
- No contact email address is displayed; the only route is a modal form
- The security page advertises HIPAA and SOC 2 while the homepage says SOC 2 Type I is only a target for H2 2026
- Google Cloud, Azure, GitLab and Teams are announced but not yet available, despite the base package mentioning GCP and GitLab
- Entry price of 500 USD per month on a twelve-month commitment, with no free plan
- No public API or product documentation could be found
- The top tier is in private beta and the company itself was only registered in November 2025
Pricing & Plans
There is no free plan: all three published tiers are paid. The lowest entry point is the Starter tier at 500 USD per month, which includes 20 agent hours per month. The Pro tier costs 1,000 USD per month for 40 agent hours with on-demand overage, and a Custom tier, currently in private beta, is quoted on request. A separate section presents the same entry point as a "Base package" from 500 USD per month, with custom add-ons and a private cloud installation quoted separately. All plans are sold on a twelve-month subscription purchased through AWS Marketplace, so the real first-year commitment at entry level is 6,000 USD, and a thirty-day money-back guarantee applies. The site displays amounts with a dollar sign only and never writes the currency code.
- investigations
- infrastructure Q&A
- on-demand SOPs
- postmortem generation
- passive autonomous notifications
- everything in Starter plus scheduled and event-triggered workflows
- automated pre-triage and documentation maintenance
- everything in Pro plus continuous infrastructure observation
- proactive issue flagging
- customer-side inference with open-source models
- custom DPA agreements and system-usage telemetry opt-out
- Base package — from 500 USD/month — MCP for agents and Slack for humans
- one cloud connected
- one version control system connected
- data kept in the customer's perimeter
- custom add-ons available
- Private cloud installation — quoted on request — all data and operations inside the customer's own cloud
- with bring-your-own encryption key and bring-your-own LLM add-ons
Data, GDPR & hosting
A consolidated view of how B.O.R.I.S handles your data.
GDPR overview
The site makes no mention of the GDPR whatsoever. Across all six pages collected there is no privacy policy, no terms of service and no legal notice; the paths that would normally carry them all return genuine 404s and are absent from the sitemap. No Article 27 EU representative is named, and no data protection officer is identified. The only contractual reference found is "Custom DPA agreements", listed as a feature of the top Custom tier, which is itself in private beta. This silence is notable because the publisher, Sirob Technologies OÜ, is established in Estonia and therefore inside the EU, with an active VAT number. What the vendor offers in place of stated compliance is an architectural argument: customer-side data residency and no third-party SaaS in the data path.
Who owns the data?
No terms of service and no privacy policy are published, so no contractual ownership clause can be read. What the vendor states is architectural rather than contractual: data lives at rest in the customer's own AWS account, described as "never B.O.R.I.S's", and the product runs inside that account under a hybrid deployment model. The FAQ states each customer is kept fully separate and that nothing is shared between customers. A private cloud installation keeps all data and operations inside the customer's own cloud. In practice the customer retains custody of the data; the absence of any published agreement means the legal allocation of rights is not verifiable from the site.
Reuse rights
Nothing on the site describes what an end user may do with data extracted from the tool, since no terms of service are published. On the vendor's side, access to connected systems is read-only by default and write actions are explicit. The layer is identity-aware, meaning it knows who is asking across AWS, GitHub and Slack. Only HIPAA-eligible AWS services sit in the data path, and the vendor states no third-party SaaS is in that path. A system-usage telemetry opt-out exists, but only on the Custom tier. The site never addresses whether customer data is used to train models.
Data retention & training
Hosting summary
Hosting is customer-side by design. The vendor operates a hybrid deployment model in which data stays at rest in the customer's own AWS account, described on the homepage as "never B.O.R.I.S's". Only HIPAA-eligible AWS services are said to sit in the data path, and the vendor states no third-party SaaS is involved in it. The security page adds that data never leaves your infrastructure and lists hybrid and self-hosted deployment options. A private cloud installation keeps all data and operations inside the customer's own cloud, with bring-your-own encryption key and bring-your-own model add-ons. Consequently no vendor hosting country or region is published, and none can be: the jurisdiction is whichever AWS region the customer selects. No privacy policy or terms exist to state a jurisdiction, a governing law or a list of subprocessors. The publisher itself is established in Tallinn, Estonia.
Things to keep in mind
Risks and trade-offs to weigh before adopting B.O.R.I.S.
- The site publishes no privacy policy, terms of service or legal notice, so no contractual commitment about your data can be checked before signing
- The security page shows HIPAA and SOC 2 while the homepage says SOC 2 Type I is only targeted for H2 2026 — an internal contradiction that should be raised with the vendor
- Announced but unavailable integrations (Google Cloud, Azure, GitLab, Teams) sit next to a base package mentioning GCP and GitLab, so confirm your stack is genuinely covered before committing
- The twelve-month subscription turns a 500 USD monthly headline into a 6,000 USD first-year commitment
- Granting an AI layer read access across your whole AWS estate, code and chat concentrates sensitive operational knowledge in one place — review the IAM scope yourself rather than trusting the read-only claim alone
- Answers presented with attached evidence are persuasive by design; teams can stop verifying and let genuine understanding of their own systems erode
- The publisher was registered in November 2025 and the top tier is in private beta, so pricing, perimeter and roadmap are all liable to change
Setup & Integrations
Technical difficulty
Setup is moderate and squarely for engineers. It requires an AWS organisation, a GitHub organisation and a Slack workspace, connected through customer-side IAM roles and OAuth, which means someone with the right to create cross-account roles must be involved. Read-only by default limits the initial blast radius, and the vendor states coding agents are configured automatically on install. A private cloud installation is available for teams wanting everything in their own perimeter. No public installation documentation was found, and purchase goes through AWS Marketplace with a sales-led demo, so expect vendor assistance rather than self-service onboarding.
Deployment
Integrations
Behind B.O.R.I.S
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement B.O.R.I.S.
Frequently asked questions
What does B.O.R.I.S actually do?
Where is my data stored?
How much does it cost and is there a free plan?
Which clouds and tools does it support today?
Does it work with my coding agent?
Is B.O.R.I.S SOC 2 or HIPAA certified?
Can I use it in Microsoft Teams or Discord?
Is my data kept separate from other customers?
Who is behind the tool?
Can I try it before buying?
Should you pick B.O.R.I.S?
B.O.R.I.S addresses a real and well-identified problem: coding and operations agents reason from the repository and miss what is actually deployed, and the people who hold that knowledge eventually leave. The answer proposed here is unusually disciplined for the category. Rather than pulling operational data into a vendor platform, B.O.R.I.S keeps it at rest in the customer's own AWS account, reads by default and writes only when told to, and exposes a single context layer to Slack, to MCP clients and to an API so that every agent in the company reads the same picture. The worked examples on the use-cases page are specific enough to be credible.
The reservations are equally concrete. The site publishes no privacy policy, no terms of service and no legal notice, and never mentions the GDPR, which is striking for a publisher established in the European Union. No contact address is shown. The security page advertises HIPAA and SOC 2 while the homepage states plainly that SOC 2 Type I is a target for the second half of 2026, so no certification can be credited today. The working perimeter is narrower than the marketing suggests: Google Cloud, Azure, GitLab and Teams are announced rather than delivered, even though the base package describes connecting one cloud "AWS or GCP".
Add an entry price of 500 USD per month on a twelve-month commitment, a top tier still in private beta, and a company registered only in November 2025, and this reads as a promising early-stage product for AWS-centric teams willing to engage with a young vendor — not yet as a settled purchase for a compliance-driven buyer.
- Choosing a selection results in a full page refresh.
- Opens in a new window.