Security & Trust
This page is maintained by AITW Authentica, the company behind Batchbind, to answer common security and privacy questions about the platform. It describes controls that are enabled in the product today. It is not a certification, an audit report or independent verification.
Last updated 27 July 2026
Shared responsibility
Security here has three layers. Batchbind operates the platform and its controls. Your workspace administrators control who is invited, what role they hold and who receives share links or inspector tokens. Your own users are responsible for their credentials and for reviewing AI output before acting on it.
Access and authentication
- Sign-in is handled by a managed authentication service; passwords are never stored by the application.
- Every user belongs to one or more workspaces, and every record is scoped to a workspace at the database level, not just in the interface.
- Roles — administrator, formulator, quality, auditor, viewer and regulator — determine what a member can see and change.
- Membership can only be granted by a workspace administrator; users cannot add themselves to a workspace.
Tenant isolation
Row-level access rules are enforced in the database for every table that holds workspace content. A query issued as one workspace cannot return another workspace's formulas, batches, documents or ledger events, regardless of how the request is made.
Tamper-evident records
Significant actions are written to an append-only ledger where each event is hash-chained to the one before it. Ledger rows cannot be edited or deleted through the application or the API. A verification routine walks the chain and reports the first inconsistent entry, so a third party can confirm a history has not been rewritten rather than taking our word for it.
Regulator and third-party access
External reviewers never receive a login to your workspace. You issue a scoped, time-boxed inspector token or share link covering named formulas, batches or engagements. Access expires on the date you set, can be revoked immediately, and every record opened during a review is recorded in an access log that both sides can see.
API keys and integrations
Machine access uses workspace-scoped API keys with explicit permissions. Keys are stored as hashes, show only a short prefix after creation, record their last use and can be revoked. Public webhook endpoints verify a signature or shared secret before any data is accepted.
Data hosting and residency
Data is hosted on managed cloud infrastructure, encrypted in transit over TLS and at rest by the storage layer, with managed backups. Each workspace selects a home region at creation and its records are held in the cell for that region. See the privacy policy for what is collected and how long it is kept.
Reporting a vulnerability
If you believe you have found a security issue, email security@batchbind.com with enough detail to reproduce it. Please give us a reasonable period to investigate before disclosing publicly, and avoid accessing data that is not yours while testing. We will acknowledge your report and keep you updated on the fix.
Security incidents
If an incident affects your workspace data we will notify workspace administrators by email with what we know, what we are doing about it and what action you should take. Security contact: security@batchbind.com.
Who operates Batchbind
Batchbind is built and operated by AITW Authentica (aitwauthentica.com). If your procurement process needs a security questionnaire completed, contact us and we will work through it with you.