Trust
Security at Baleena
Baleena builds runtime governance for AI agents, so security is part of what we sell, not an afterthought. This page explains how we approach security and how to report a vulnerability to us.
Report a vulnerability: security@getbaleena.com. Our machine-readable contact details are in /.well-known/security.txt.
Overview
Baleena sits at the execution boundary of AI agents. It resolves which capability an agent is trying to use, evaluates explicit policy before the action runs, routes risky actions to human review, and verifies what actually happened. The principles that shape the product (explicit authority, least privilege, and an auditable trail for every action) also shape how we run the company.
Hosting and architecture
This website
- getbaleena.com is a static website. It has no user accounts, no login, and no forms that collect data.
- All traffic is served over HTTPS. Requests over plain HTTP, and to www.getbaleena.com, are permanently redirected to https://getbaleena.com.
- The site does not set cookies and does not use analytics or advertising trackers.
- The only third-party resource the site loads is web fonts from Google Fonts.
The Baleena platform
Baleena can be deployed as a managed cloud service, in a dedicated private cloud, or on-premises in the customer's own environment. With the private-cloud and on-premises options, customers keep infrastructure, data, and governance workflows inside boundaries they control.
Security architecture documentation for a given deployment model is available to customers and prospective customers on request.
Data protection principles
- Data minimization. We collect and keep only the data needed to provide the service.
- Customer ownership. Customer data belongs to the customer and is used only to provide the service the customer has asked for.
- Deployment choice. Customers with strict data-residency or isolation requirements can run Baleena in their own environment.
- Auditability. Governed actions leave a traceable record, so decisions can be reviewed after the fact.
Encryption
All connections to getbaleena.com are encrypted in transit using TLS. Encryption details for the Baleena platform depend on the deployment model and are covered in our customer security documentation.
Access control principles
- Least privilege. People and systems get only the access they need for their role, and that access is removed when it is no longer needed.
- Explicit authority. Sensitive actions require explicit authorization. They are never implied by having network access or holding a credential.
- Accountability. Administrative actions should be attributable to an individual and reviewable.
Reporting a vulnerability
If you believe you have found a security vulnerability in getbaleena.com or in a Baleena product, please tell us. We welcome reports from security researchers and customers.
How to report
- Email security@getbaleena.com. English and Turkish are both fine.
- Describe the issue, the affected URL or component, and the steps to reproduce it. Include a proof of concept if you have one.
- Tell us how you would like to be credited, if at all.
What to expect
- We aim to acknowledge your report within three business days.
- We will investigate, keep you informed of our progress, and let you know when the issue is resolved.
- We ask that you give us reasonable time to fix the issue before disclosing it publicly.
Good-faith research
We will not pursue legal action against anyone who researches and reports a vulnerability in good faith and in line with this policy. Good faith means you:
- avoid privacy violations, data destruction, and disruption to our service or our customers;
- access only the minimum data needed to demonstrate the issue, and do not keep it;
- do not use denial-of-service testing, spam, social engineering, or physical attacks.
Security questions
If you are evaluating Baleena and need to complete a security questionnaire or review our practices, contact info@getbaleena.com.