Data Management

Bitaic manages monitoring, configuration, account, audit, session, and integration data with scoped access, encrypted transport, managed encryption at rest, retention controls, export workflows, and deletion request handling.

Data Management Principles

  • Collect the operational data needed to run monitoring, alerting, troubleshooting, reporting, and account administration workflows.
  • Protect data in transit with TLS and protect stored data with managed encryption at rest.
  • Restrict data access through workspace roles, explicit service-token scopes, and local host permissions where agents run.
  • Provide dashboard and API export paths for customers who need to analyze, archive, or transfer their own monitoring data.

Data Collection

Bitaic collects product-specific monitoring data through managed checks, installed agents, CLI workflows, API operations, and integrations.

  • Endpoint and SSL data: availability, status code, redirects, response time, certificate status, expiration, chain health, issuer metadata, and alert state.
  • Domain and DNS data: domain status, public registry metadata, renewal window, nameserver drift, DNSSEC state, resolver results, TTL, latency, propagation state, and alert state.
  • Host and Windows Event data: CPU, memory, disk, disk I/O, agent freshness, event IDs, levels, sources, timestamps, matched rules, and delivery state.
  • Account and administration data: user profile fields, roles, session records, audit records, integration configuration, webhook subscriptions, and token metadata.

Storage And Security

  • User, API, webhook, agent, and service traffic uses TLS in transit.
  • Stored customer monitoring data, configuration data, account/profile data, audit records, session records, token metadata, and integration configuration are protected by managed encryption at rest.
  • Workspace roles and API scopes decide who can view, change, export, or administer stored data.
  • Bitaic does not store or display registrant personal contact fields collected from WHOIS or RDAP sources for Domain Monitoring.

Retention And Deletion

  • Active monitoring and audit history use a 12-month default retention baseline unless a workspace policy or customer contract sets a different period.
  • Webhook delivery attempts are retained for 30 days, and local agent buffers retain temporary data up to the product-specific buffer cap.
  • Deletion requests remove qualifying customer data from active product surfaces after verification and processing.
  • Retained backups age out through the backup lifecycle, and legal or security holds can pause deletion when required.

Export And Portability

  • Dashboard exports and API export jobs support CSV and JSON output for monitoring data, alerts, audit records, and other supported workspace data.
  • Exports can be filtered by date range, target, check, product area, event type, or other supported fields.
  • Export permissions follow least privilege: read-only monitoring exports can use Viewer access, while audit, user, token, webhook, and integration exports require Admin or an approved API-access scope.