Trust

Security at Baleena

Baleena builds runtime governance for AI agents, so security is part of what we sell, not an afterthought. This page explains how we approach security and how to report a vulnerability to us.

Last updated: 29 September 2026

Report a vulnerability: security@getbaleena.com. Our machine-readable contact details are in /.well-known/security.txt.

Overview

Baleena sits at the execution boundary of AI agents. It resolves which capability an agent is trying to use, evaluates explicit policy before the action runs, routes risky actions to human review, and verifies what actually happened. The principles that shape the product (explicit authority, least privilege, and an auditable trail for every action) also shape how we run the company.

Hosting and architecture

This website

The Baleena platform

Baleena can be deployed as a managed cloud service, in a dedicated private cloud, or on-premises in the customer's own environment. With the private-cloud and on-premises options, customers keep infrastructure, data, and governance workflows inside boundaries they control.

Security architecture documentation for a given deployment model is available to customers and prospective customers on request.

Data protection principles

Encryption

All connections to getbaleena.com are encrypted in transit using TLS. Encryption details for the Baleena platform depend on the deployment model and are covered in our customer security documentation.

Access control principles

Reporting a vulnerability

If you believe you have found a security vulnerability in getbaleena.com or in a Baleena product, please tell us. We welcome reports from security researchers and customers.

How to report

  1. Email security@getbaleena.com. English and Turkish are both fine.
  2. Describe the issue, the affected URL or component, and the steps to reproduce it. Include a proof of concept if you have one.
  3. Tell us how you would like to be credited, if at all.

What to expect

Good-faith research

We will not pursue legal action against anyone who researches and reports a vulnerability in good faith and in line with this policy. Good faith means you:

Security questions

If you are evaluating Baleena and need to complete a security questionnaire or review our practices, contact info@getbaleena.com.