Security Overview
Bitaic security controls help teams protect monitoring data, workspace access, service tokens, integrations, sessions, and administrative activity. Start here for the security baseline, then use the dedicated pages for audit logs, logging, roles, and sessions.
Security Baseline
| Area | Behavior |
|---|---|
| Access control | Workspace roles are Viewer, Operator, and Admin, with scoped service tokens for automation. |
| Encryption | User, API, webhook, agent, and service traffic uses TLS, and stored customer data is protected by managed encryption at rest. |
| Audit | Audit records cover authentication, roles, sessions, monitoring configuration, agents, tokens, webhooks, integrations, exports, deletion requests, and sensitive data access. |
| Sessions | Sessions support inactivity expiration, manual logout, Admin revocation, audit events, and session/device review. |
Recommended Practices
- Give each user and service token the narrowest access needed for its job.
- Enable MFA for user accounts and protect automation secrets outside of source control.
- Review audit logs after role, token, webhook, integration, export, deletion, and monitoring-configuration changes.
- Keep local host permissions separate from workspace roles when installing or running agents.