Security & Compliance
Baton is built for regulated industries. Every AI decision is auditable. Every agent is bounded. Your data stays in your cloud.
EU AI Act Article 12 Ready
Full prompt-to-commit audit trail with chain of custody. Every AI interaction logged with timestamp, author, story reference, Constraint Object snapshot, and resulting commit hash. Enforcement begins August 2026.
Full Prompt Audit Trail
Every prompt sent to a worker, every response generated, every human accept/reject decision. The Constraint Object is logged at generation time — it proves what the agent knew and was bound by.
BYOL — Bring Your Own LLM
Models run in your cloud. Baton supports Anthropic Claude, AWS Bedrock, Google Gemini, Cohere Command A (self-hostable on 2 GPUs), and Ollama. No data leaves your infrastructure.
Constraint Objects as Audit Artifacts
Every card generates a structured, machine-readable Constraint Object before any worker runs. It is the artifact you show a regulator when they ask: how do you know the agent stayed within safe boundaries?
SOC 2 Type II
SOC 2 Type II certification planned. Security-first architecture with role-based access control, encrypted data at rest and in transit, and comprehensive logging.
Single-Tenant by Design — Runs in Your VPC
Every Baton instance is single-tenant: your code, PRs, and PRDs are never pooled with another customer's. Enterprise deployments run entirely inside your own AWS account — Terraform-packaged, with Bedrock inference — for GDPR, PIPEDA, and industry-specific residency requirements.
Built for the question your regulator will ask
“How do you know the AI agent stayed within safe boundaries?” Baton's Constraint Object is the answer. Not a markdown file. Not a prompt suggestion. A structured, machine-enforced specification — logged as an audit artifact.
Talk to Us About Compliance