Security

Security and compliance

Agents touch production systems and customer data, so the boring controls matter more than the demo. Here is what we hold, what we log, and where your data lives.

SOC 2 Type II

Audited annually by an independent firm. Full report available under NDA.

GDPR

EU data processing agreement, DPIA support, and EU-only residency on request.

HIPAA

BAA available on Enterprise. PHI is excluded from trace payloads by default.

ISO 27001

Certified information security management system, reviewed each year.

How we operate

Encryption

TLS 1.3 in transit and AES-256 at rest. Trace payloads are encrypted with per-workspace keys.

Access control

SSO via SAML or OIDC, SCIM provisioning, and role-based access down to the individual agent.

Data residency

Choose US or EU storage, or run the control plane entirely inside your own VPC.

Audit logging

Every configuration change, key issue, and trace export is logged and retained for one year.

Penetration testing

Third-party tests twice a year, plus continuous automated scanning against every release.

Incident response

On-call rotation with a one-hour acknowledgement target and public post-incident write-ups.

FAQ

Questions engineers actually ask

The things teams want settled before they put an agent in front of a customer.

Still deciding?

Read the quickstart and get a live trace out of your own agent in about ten minutes.

Which models can Baton drive?

Can we run Baton in our own infrastructure?

How do typed tool contracts work?

How is an agent run counted?

What happens when an agent is uncertain?

Do you retain our prompts and outputs?

Which models can Baton drive?

Can we run Baton in our own infrastructure?

How do typed tool contracts work?

How is an agent run counted?

What happens when an agent is uncertain?

Do you retain our prompts and outputs?

Create a free website with Framer, the website builder loved by startups, designers and agencies.