Compliance

Bitaic provides controls and documentation that help customers evaluate infrastructure monitoring data for their own compliance programs. The compliance baseline focuses on security controls, access controls, audit records, retention, export, deletion, and privacy request workflows.

Control Areas

AreaBehavior
EncryptionUser, API, webhook, agent, and service traffic uses TLS in transit. Stored customer monitoring, configuration, account, audit, session, token metadata, and integration configuration are protected by managed encryption at rest.
Access controlWorkspaces use Viewer, Operator, and Admin roles, explicit service-token scopes, and local host permissions for agent-side operating-system access.
Audit recordsAudit logs cover authentication, roles, users, sessions, monitoring configuration, agents, tokens, webhooks, integrations, exports, deletion requests, and sensitive data access.
Retention and deletionActive monitoring and audit history use a 12-month default retention baseline unless a workspace policy or customer contract sets a different period. Deletion requests remove qualifying data from active product surfaces after verification and processing.
ExportsCSV and JSON exports are available through dashboard and API jobs with least-privilege permissions.

Privacy And Data Rights

Users and workspace administrators can request access, correction, export, deletion, or other privacy actions when supported by applicable law, customer agreement, or Bitaic policy. The Privacy Policy is the customer-facing policy record for data collection, processing, retention, and rights requests.

Customer Responsibilities

  • Assign the narrowest workspace roles and API scopes needed for each user, service token, export, integration, or automation workflow.
  • Store exported data and API credentials in systems that match your own compliance requirements.
  • Review audit records after role, token, webhook, integration, retention, or deletion changes.
  • Confirm contractual terms before using Bitaic for regulated data or jurisdiction-specific compliance requirements.

Incident And Breach Handling

Bitaic handles suspected security or privacy incidents through triage, containment, assessment, remediation, customer communication when required, and post-incident review. Notifications are provided according to applicable law and customer agreements.