This Security Policy and Security Addendum ("Security Addendum") describes the administrative, technical and organisational safeguards BACI LLC ("BACI") maintains to protect the confidentiality, integrity, availability and resilience of BACI Services and Customer Data.
Where incorporated into an Agreement, the contractual provisions of this Security Addendum constitute BACI's security commitments for the applicable Services. The controls described here are risk-based and may be implemented through BACI systems, personnel, infrastructure providers and authorised service providers. BACI may evolve individual controls as technology and threats change, provided the overall level of protection applicable to Customer Data is not materially reduced during the applicable Service term.
This Security Addendum applies to BACI Services and to Customer Data processed by BACI in connection with those Services, subject to the applicable Agreement, Order, Service configuration and any product-specific or regional Supplemental Terms.
It addresses BACI's security governance, access control, infrastructure, application security, cryptography, vulnerability management, monitoring, incident response, resilience, personnel security, third-party risk and related safeguards.
Customer-controlled devices, networks, identity systems, credentials, configurations, integrations and third-party services remain subject to Customer's own security responsibilities except to the extent BACI expressly agrees otherwise.
This Security Addendum forms part of the BACI Legal Framework.
Under the Terms of Service order of precedence, this Security Addendum governs contracted security obligations for the matters it expressly addresses. The Data Processing Addendum governs BACI's Processing of Customer Personal Data on Customer's behalf. The Service Level Agreement governs service-level commitments and remedies. An executed Order, Statement of Work or amendment may impose additional security requirements where it expressly addresses them.
Nothing in this Security Addendum reduces a mandatory security obligation imposed by Applicable Law.
BACI will maintain a security programme appropriate to the nature, scale and risk of the Services.
The programme may include documented security policies and standards; assigned security responsibilities; risk assessment; access governance; secure development requirements; vulnerability management; incident response; business continuity and recovery planning; third-party risk management; personnel controls; security awareness; monitoring; and periodic review of material controls.
Security controls will be selected and operated using a risk-based approach that considers the sensitivity of information, foreseeable threats, Service architecture, Customer configuration and consequences of compromise.
BACI will assign responsibility for material security functions to appropriate personnel.
Personnel with security responsibilities may establish standards, coordinate incident response, review material risks, oversee remediation, evaluate third-party risk and support security governance.
Security is a shared responsibility. BACI is responsible for controls within the Services and systems under BACI's control. Customer is responsible for controls within Customer-controlled environments and for appropriate use and configuration of BACI functionality.
BACI will maintain processes reasonably designed to identify, assess, prioritise and address material security risks affecting the Services.
Risk-management activities may include architecture review, threat assessment, vulnerability assessment, control review, vendor assessment, incident analysis and evaluation of material changes to the Services.
BACI may prioritise remediation based on severity, exploitability, exposure, affected assets, available mitigations and foreseeable impact.
BACI will maintain reasonable processes for identifying and managing material production systems, infrastructure and information assets under BACI's control.
Access to production systems will be restricted according to operational need. BACI may use automated inventory, configuration, infrastructure-as-code, cloud-provider controls and other mechanisms appropriate to its architecture.
BACI will maintain controls designed to restrict access to systems and Customer Data to authorised persons and services.
Controls may include unique identities, authentication, role-based or attribute-based access, least-privilege principles, separation of duties where appropriate, privileged-access restrictions, access approval, access revocation and periodic access review.
Administrative access to production environments will be limited to personnel with a legitimate operational requirement.
BACI will revoke or adjust access within a reasonable period when access is no longer required or an individual's role materially changes.
BACI will use authentication controls appropriate to the sensitivity and privilege of the relevant system.
BACI may require stronger authentication for privileged, administrative or otherwise sensitive access.
Where BACI controls the authentication system, BACI will not intentionally store user passwords in readable plaintext.
Customers are responsible for safeguarding their credentials, selecting appropriate authentication options available to them and promptly addressing suspected credential compromise.
Privileged access will be restricted to authorised personnel and services with a legitimate requirement.
BACI will use reasonable controls designed to reduce unnecessary standing privilege and to protect privileged credentials.
Privileged activity may be logged or monitored where appropriate to the system and risk.
The existence of technical access does not itself authorise personnel to access Customer Data for unrelated purposes.
BACI will maintain controls designed to preserve logical separation between Customer environments and authorised organisational contexts.
Where BACI Services use tenant, organisation or workspace boundaries, BACI will implement access-control and application controls designed to prevent one Customer from obtaining unauthorised access to another Customer's protected data.
BACI will treat failures of material tenant-isolation controls as security issues requiring appropriate investigation and remediation.
BACI personnel access to Customer Data will be limited to circumstances reasonably necessary to provide, secure, support, maintain or troubleshoot the Services; execute Customer instructions; investigate abuse or security events; comply with law; or perform another purpose authorised by the Agreement.
BACI will seek to minimise unnecessary access to Customer Data and may use technical, procedural or architectural controls to reduce exposure.
BACI will use encryption or equivalent protective controls appropriate to the risk for Customer Data transmitted over public networks and for protected Customer Data stored within applicable production systems where technically appropriate.
BACI will use recognised cryptographic protocols and implementations appropriate to the relevant environment.
Cryptographic keys and secrets under BACI's control will be protected through reasonable access restrictions and lifecycle controls appropriate to their purpose.
Specific algorithms, key lengths and implementations may change as security standards evolve.
BACI will maintain reasonable controls for protecting production secrets, API credentials, service credentials, cryptographic material and other sensitive authentication information under BACI's control.
BACI will not intentionally place production secrets in publicly accessible source repositories.
Where compromise is suspected, BACI may rotate, revoke or replace affected credentials or secrets.
BACI will maintain network and infrastructure controls appropriate to the Service architecture.
Controls may include network segmentation, firewall or security-group controls, restricted administrative interfaces, encrypted communications, cloud security controls, denial-of-service protections, threat detection, environment separation and hardened configuration.
BACI may rely on reputable infrastructure providers for physical facilities and underlying cloud infrastructure, subject to BACI's third-party risk and contractual framework.
BACI will use reasonable controls to distinguish production environments from development, testing or other non-production environments.
Customer Data will not be copied into non-production environments unnecessarily. Where production-derived data is required for legitimate testing or support, BACI will apply protections appropriate to the sensitivity and purpose, including minimisation, masking, restricted access or other safeguards where reasonably practicable.
BACI will maintain secure development practices appropriate to the Services.
Practices may include security requirements, code review, dependency management, automated testing, static or dynamic analysis where appropriate, secrets detection, vulnerability scanning, change control, architecture review and security assessment for material features.
Security considerations will be incorporated into development and deployment processes proportionate to the risk of the change.
Material production changes will be subject to reasonable change-management controls designed to reduce unintended security and availability impact.
Controls may include version control, review, testing, automated deployment controls, approval requirements, rollback capability and monitoring.
Emergency changes may follow expedited procedures where necessary to protect security or restore Service.
BACI will maintain processes designed to identify, assess, prioritise and remediate vulnerabilities affecting systems under BACI's control.
Sources may include automated scanning, dependency alerts, infrastructure-provider notifications, penetration testing, security research, internal review and vulnerability reports.
Remediation priority will be risk-based. BACI may use compensating controls where immediate remediation is not reasonably practicable.
BACI will not represent that any system is free from all vulnerabilities.
BACI will perform security testing appropriate to the nature and maturity of the Services.
Testing may include automated vulnerability scanning, application-security testing, configuration review, dependency analysis, penetration testing or other assurance activities.
Independent testing may be performed where appropriate to BACI's risk profile and contractual commitments.
Customer security testing of BACI systems requires prior written authorisation unless BACI publishes a programme expressly permitting such testing.
BACI will maintain controls reasonably designed to detect, prevent or contain malicious activity appropriate to the systems involved.
Controls may include endpoint protections, infrastructure monitoring, malicious-file detection, restricted execution, dependency controls, email protections and threat-detection capabilities.
BACI may isolate or restrict systems, credentials or functionality where reasonably necessary to address an active threat.
BACI will maintain logging and monitoring appropriate to material production systems and security risks.
Logs may record authentication events, administrative activity, application events, infrastructure events, security alerts, API activity and other information reasonably necessary for security, reliability, investigation and compliance.
Access to security logs will be restricted appropriately.
Retention of logs will be determined according to security purpose, Service architecture, Applicable Law, the Data Retention & Deletion Policy and contractual requirements.
BACI may use automated and manual mechanisms to detect anomalous or potentially malicious activity.
Security alerts may be prioritised based on severity, confidence, affected systems and potential impact.
BACI will maintain processes for escalation of material alerts to personnel capable of investigation and response.
BACI will maintain an incident-response process designed to identify, assess, contain, investigate, remediate and recover from material security incidents.
The process may include incident classification, escalation, evidence preservation, containment, eradication, recovery, communications, post-incident review and corrective action.
BACI may engage infrastructure providers, Subprocessors, forensic specialists, legal advisers or other appropriate parties where necessary to investigate or respond to an incident.
Where a Security Incident affects Customer Personal Data processed by BACI on Customer's behalf, BACI will provide notice in accordance with the Data Processing Addendum.
Where a material security incident affects Customer Data but falls outside the DPA's definition of Security Incident, BACI will provide notification where required by the Agreement or Applicable Law.
Notification may be provided in phases as material information becomes reasonably available.
Notification is not an admission of fault or liability.
Security incidents should be reported to security@bacihq.com.
BACI may use designated Customer security, administrative or contractual contacts to provide incident communications.
Customers are responsible for maintaining accurate contact information where the Services provide a mechanism for doing so.
BACI will maintain backup and recovery measures appropriate to the Services and data architecture.
Backup frequency, retention and recovery design may vary by Service, data type and architecture.
Backups will be protected using safeguards appropriate to the sensitivity of the information.
Deletion of data from backups may occur through ordinary secure backup rotation where immediate deletion is not technically practicable and Applicable Law permits.
BACI will maintain reasonable business-continuity and disaster-recovery arrangements for material Service functions.
Measures may include redundancy, backups, infrastructure recovery procedures, documented response processes, restoration priorities and periodic review or testing.
Specific availability commitments, recovery-time commitments or recovery-point commitments apply only where expressly stated in an SLA, Order or Supplemental Terms.
BACI will design and operate material Services with resilience measures appropriate to their architecture and commercial purpose.
BACI may use redundancy, automated recovery, load distribution, infrastructure monitoring and capacity controls.
This Security Addendum does not independently create an uptime guarantee. Contractual uptime commitments and remedies are governed by the applicable Service Level Agreement or Order.
Where BACI uses third-party cloud or data-centre infrastructure, physical security of those facilities may be operated by the applicable infrastructure provider.
BACI will select infrastructure providers using reasonable security and risk considerations and will rely on contractual commitments and available assurance information appropriate to the relationship.
BACI-controlled offices and equipment will be subject to physical protections appropriate to the information and systems present.
BACI will apply reasonable personnel-security measures to individuals with access to material systems or Customer Data.
Measures may include confidentiality obligations, role-appropriate access, onboarding and offboarding controls, security awareness and disciplinary processes.
Background screening may be used where lawful, appropriate to the role and reasonably justified by risk. This Security Addendum does not represent that every BACI worker is subject to the same screening in every jurisdiction.
BACI personnel with relevant responsibilities will receive security awareness or role-appropriate security guidance.
Personnel performing specialised security, engineering or administrative functions may receive additional training appropriate to their responsibilities.
BACI may update training as threats, technologies and legal requirements evolve.
BACI will assess material service providers and Subprocessors using security and privacy criteria appropriate to the services they provide and the information they process.
Where a third party processes Customer Personal Data on BACI's behalf, BACI will impose appropriate contractual data-protection and security obligations in accordance with the DPA.
BACI may consider available certifications, audit reports, security documentation, architecture, contractual commitments, incident history and other relevant factors.
Use of a third party does not eliminate BACI's contractual responsibilities to the extent provided by the Agreement.
BACI may use cloud, hosting, networking, communications, security and other infrastructure providers.
Responsibilities will be allocated according to the relevant service model. BACI remains responsible for configuration and controls within BACI's scope, while infrastructure providers may be responsible for underlying facilities, hardware, hypervisors, managed services or other provider-controlled components.
BACI will not claim that a provider's certification automatically certifies BACI unless BACI is expressly within the applicable certification scope.
Customer is responsible for security matters under Customer's control, including safeguarding credentials; managing Authorised Users; configuring permissions; promptly removing unnecessary access; securing Customer devices and networks; securing Customer-controlled integrations; maintaining appropriate endpoint protections; reviewing BACI configuration choices; protecting API credentials; maintaining lawful and appropriate connected-system permissions; and promptly notifying BACI of suspected compromise affecting the Services.
Customer must not disable, bypass or materially weaken BACI security controls except where BACI expressly permits configuration of the relevant control.
Customer remains responsible for determining whether the Services and selected configuration satisfy Customer's own regulatory and security requirements.
BACI will apply security controls appropriate to BACI-controlled APIs and integrations.
Customers and developers must protect credentials, use authorised authentication mechanisms, respect rate and access controls and avoid exposing secrets in client-side code or public repositories.
BACI may revoke, rotate or restrict API credentials where reasonably necessary for security, legal compliance or material breach.
Third-party integrations may create security dependencies outside BACI's control; Customer is responsible for evaluating and authorising those integrations.
Where Customer enables Autonomous functionality, BACI will apply applicable technical authority boundaries and supported controls configured within the Service.
Such controls may include action permissions, approval thresholds, financial or spending limits, market or channel restrictions, connected-system permissions, frequency or volume controls and other configured constraints.
BACI will not treat the mere technical capability of a connected system as Customer authorisation for an Autonomous Action.
Customers are responsible for configuring authority boundaries appropriate to the consequence of permitted actions.
Autonomy does not remove governance.
BACI may implement security controls for AI-enabled functionality, including controls addressing access, prompt and input handling, output handling, model-provider access, abuse prevention, tool permissions, data isolation and monitoring.
BACI will not use private Customer Personal Data, Customer Confidential Information, private Inputs or private Outputs for general-purpose or shared model training for the benefit of other customers unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, consistent with the Terms and DPA.
Third-party AI providers that process Customer Personal Data on BACI's behalf are subject to BACI's applicable Subprocessor and contractual framework.
BACI will maintain safeguards reasonably designed to reduce unauthorised disclosure or exfiltration of Customer Data.
Controls may include access restrictions, tenant isolation, authentication, encryption, monitoring, secret protection, application controls and incident detection.
No technical control can eliminate all risk. Customer should avoid placing data into BACI that the applicable Service is not authorised to process.
BACI will retain and delete Customer Data in accordance with the Agreement, Data Processing Addendum, Data Retention & Deletion Policy, Customer instructions where applicable and Applicable Law.
Where storage media or cloud resources are retired or reallocated, BACI will rely on deletion, sanitisation or provider controls appropriate to the storage technology and risk.
Backup deletion may occur through ordinary secure rotation where permitted.
BACI support personnel will access Customer Data only where reasonably necessary to provide requested support, troubleshoot, secure or maintain the Services, or as otherwise authorised by the Agreement.
Support access may be logged, time-limited, permission-controlled or otherwise restricted where appropriate.
Customers should not provide passwords, private keys or other unnecessary secrets in support communications.
Where BACI personnel remotely access production systems, BACI will use reasonable controls appropriate to the privilege and risk of the access.
Controls may include authenticated access, encrypted connections, managed identities, device controls, privileged-access restrictions, logging and session controls.
Direct public exposure of sensitive administrative interfaces will be restricted where reasonably practicable.
BACI will maintain reasonable configuration practices for material production systems.
BACI may use hardened baselines, infrastructure-as-code, automated configuration, provider-recommended security settings, patching and configuration monitoring.
Configuration standards may vary by technology and will evolve as systems change.
BACI will maintain processes for evaluating and applying security patches and updates to systems within BACI's control.
Patch priority and timing will be risk-based and may consider severity, exploitability, exposure, operational impact, vendor guidance and available compensating controls.
Emergency security patches may be deployed through expedited change procedures.
BACI will use reasonable measures to manage security risks arising from software dependencies, packages, build processes and deployment pipelines.
Measures may include dependency scanning, version control, restricted repository access, build controls, secrets scanning, package review and remediation of known material vulnerabilities.
BACI may replace or update dependencies where reasonably necessary to maintain security.
Access to non-public BACI source code and repositories will be restricted to authorised personnel and services with a legitimate requirement.
BACI will use access controls and version-management practices appropriate to its development environment.
Customers receive no right to access BACI source code except where expressly granted in writing.
BACI may make reasonable security documentation available to eligible Customers under appropriate confidentiality restrictions.
Where BACI obtains independent certifications, assessments, penetration-test summaries or audit reports, BACI may make applicable materials available according to their confidentiality, licensing and distribution restrictions.
BACI will not state that it holds SOC, ISO, government, industry or other certification unless that status has actually been obtained and remains applicable.
Customer audit rights concerning Customer Personal Data are governed by the DPA and applicable Agreement.
BACI may respond to reasonable enterprise security questionnaires concerning the Services.
Where information is already addressed by current security documentation, BACI may satisfy a request by providing or referencing that documentation.
BACI may decline to disclose information that would create a security risk, reveal another Customer's information, disclose privileged material, violate law or expose sensitive internal defensive details.
Customer must not conduct penetration testing, vulnerability scanning, load testing, denial-of-service testing or other intrusive testing against BACI without prior written authorisation unless BACI publishes a programme expressly permitting the activity.
Authorised testing must comply with the scope, timing, rate, reporting and safety requirements specified by BACI.
BACI may terminate testing that creates material risk to the Services or other Customers.
Security researchers and Customers may report suspected BACI vulnerabilities to security@bacihq.com.
Reports should provide sufficient technical information to permit reasonable investigation and should avoid unnecessary access to Customer Data, privacy violations, service disruption or destructive testing.
The existence of this reporting channel does not itself authorise testing otherwise prohibited by the Acceptable Use Policy or this Security Addendum.
BACI will comply with security obligations directly applicable to BACI under Applicable Law.
Where Customer is subject to industry-specific requirements, Customer is responsible for determining whether BACI has expressly agreed to support those requirements.
BACI will not represent that an ordinary Service environment satisfies a specialised regulatory regime, government accreditation or industry certification unless BACI has established the necessary contractual and factual basis.
Government and public-sector Customers may be subject to additional security requirements under the Government & Public Sector Schedule, applicable Order or Supplemental Terms.
Classified information, controlled government information or information requiring specialised accreditation must not be submitted to an ordinary BACI environment unless BACI expressly authorises the environment for that category.
BACI will not claim a government security accreditation that BACI has not obtained.
Data residency is not itself a complete security control. Processing location may depend on Service architecture, infrastructure providers, Customer configuration, support, security, resilience and legal requirements.
BACI will not promise exclusive processing within a particular jurisdiction unless that commitment is expressly included in the applicable Order or Supplemental Terms.
Where a contracted residency configuration applies, BACI will operate it according to the applicable contractual terms.
BACI may modify security controls as technology, Services, threats, providers and legal requirements evolve.
BACI may replace a control with another control that provides substantially equivalent or improved protection.
During an applicable Service term, BACI will not materially reduce the overall security of the contracted Services in a manner inconsistent with the Agreement.
If BACI becomes aware that a material change under BACI's control has materially reduced the overall security protections contractually applicable to Customer Data, BACI will take reasonable steps to remediate the degradation.
Where the change materially affects a contracted security commitment and cannot reasonably be remediated, the parties will address the matter under the Agreement and any applicable enterprise contractual process.
BACI maintains safeguards designed to manage security risk, but no internet-connected or software system can guarantee absolute security.
This provision does not reduce BACI's obligation to implement the safeguards expressly required by the Agreement or Applicable Law.
BACI will seek to ensure that material security representations made in this Security Addendum and formal BACI security documentation accurately describe BACI's applicable controls.
BACI will not knowingly represent that it maintains a certification, control, architecture, geographic restriction, encryption commitment, testing programme or other security capability that BACI does not actually maintain.
Descriptions of planned or future controls will not be presented as existing contracted controls until implemented.
BACI may preserve relevant security logs, system records, forensic information and other evidence where reasonably necessary to investigate an incident, protect systems, comply with law or establish, exercise or defend legal claims.
Preserved information will remain subject to applicable confidentiality, privacy, security and retention requirements.
BACI will not provide governments or law-enforcement authorities with unrestricted access to Customer environments merely in response to an informal request.
Requests for Customer Data will be handled under the Terms, Privacy Policy, DPA and Applicable Law.
Where legally permitted and reasonably practicable, BACI may notify the affected Customer and may seek clarification, narrowing or legal review of requests reasonably believed to be unlawful, defective or materially overbroad.
Customer will reasonably cooperate with BACI in addressing security events associated with Customer-controlled credentials, configurations, users, integrations or systems.
BACI will reasonably cooperate with Customer concerning material security matters affecting the Services, subject to the Agreement, confidentiality, security and Applicable Law.
Neither party is required to disclose information that would materially compromise another customer's security or violate legal obligations.
This Security Addendum describes BACI's baseline security commitments for applicable Services. Product-specific, regulated or enterprise requirements apply only where expressly incorporated through an Order, Security Schedule, Statement of Work or other applicable Supplemental Terms.
Security commitments do not create service credits, warranties or remedies beyond those provided by the Agreement unless expressly stated.
Liability arising from security matters is governed by the liability, indemnity, exclusion and enhanced-cap provisions of the applicable Agreement.
This Security Addendum does not create a separate or duplicative liability cap.
Nothing in this Security Addendum limits liability to the extent limitation is prohibited by Applicable Law.
This Security Addendum applies while BACI provides the applicable Services and for as long thereafter as BACI retains Customer Data subject to security obligations under the Agreement.
Security obligations that by their nature apply to retained Customer Data survive termination for the period the relevant data remains retained.
BACI may update this Security Addendum to reflect changes in technology, Services, threats, providers, security practices, Applicable Law or the BACI Legal Framework.
Each version will identify its effective date and last-updated date.
BACI will not use a unilateral update to materially reduce an express contracted security commitment during an existing Service term where the Agreement or Applicable Law prohibits that reduction.
Examples of controls in this Security Addendum are illustrative unless expressly stated as mandatory.
A statement that BACI "may" use a particular control does not represent that every listed technology is deployed in every environment.
A statement that BACI "will" maintain a safeguard is a contractual commitment where this Security Addendum is incorporated into the Agreement, subject to its stated scope and qualifications.
Where a mandatory provision of Applicable Law requires greater protection, the mandatory provision controls to the extent of the inconsistency.
Security questions, suspected vulnerabilities and security incidents may be directed to:
BACI Security BACI LLC security@bacihq.com
Privacy matters may be directed to privacy@bacihq.com.
The following control domains form BACI's baseline technical and organisational security framework for applicable Services:
The exact technical implementation may evolve provided BACI maintains protection appropriate to the risk and does not materially reduce the overall contracted security level during the applicable Service term.
BACI's incident-response lifecycle may include:
The sequence may vary according to the nature and urgency of the incident.
BACI Responsibility: security of BACI-controlled application and infrastructure configurations; BACI personnel access; BACI-controlled code and deployment processes; BACI security monitoring; BACI incident response; BACI-managed credentials and secrets; BACI's Subprocessor security framework; and contractual security measures expressly assigned to BACI.
Customer Responsibility: Customer user lifecycle; Customer-selected permissions; Customer endpoints and local networks; Customer-controlled identity-provider configuration; Customer API-key handling after issuance; Customer-controlled integrations; Customer data classification and lawful submission; Customer selection of appropriate Service configuration; Customer review of Autonomous authority boundaries; and response to compromise within Customer-controlled systems.
Shared Responsibility: authentication configuration where Customer options exist; integration security; incident coordination; regulatory security assessment; data minimisation; access review; and secure operation of connected systems.
The applicable Agreement, Order and Service architecture control if a specific responsibility differs from this baseline matrix.
BACI SECURITY POLICY AND SECURITY ADDENDUM — VERSION 1.0 Effective 10 September 2026
We're listening.