Privacy
What we store
Baaito stores the account identity you sign in with, the organisation you belong to, your role, and the documents, projects and sources your organisation creates in the workspace. Generated documents, their inputs, runs and versions stay inside the organisation that produced them.
Organisation isolation
Every workspace record carries an owning organisation. Access rules are enforced in the database, so a request signed with one organisation's session cannot read or write another organisation's documents, projects, prompts or integration settings.
Access and audit
Sign-in, invitation, role change, administration and integration configuration events are recorded in an audit trail visible to organisation administrators and auditors.
Model providers and keys
Provider credentials supplied by your organisation are stored server-side and are never returned to the browser. Documents are sent to the model provider your organisation's routing policy selects.
Deletion
An organisation owner can request deletion of organisation content. Removing a member immediately ends their access to organisation content.