We never store credentials
BatonPass operates downstream of your agent's authenticated session. Operators see what your agent saw — they never receive, type, or store passwords. The browser snapshot captures DOM + cookies for state restoration, with cookie values encrypted at rest with per-tenant keys.
Explicit human authorization
Every handoff requires the operator to: (1) open the signed mobile URL, (2) tap a physical action on screen, (3) confirm submit. No background or autonomous actions. The agent only resumes after the operator explicitly hits Resume.
Audit logs you can ship to compliance
Every state transition (created → detected → frozen → notified → opened → solving → solved → resumed → completed) is timestamped, tamper-evident (hash chain), and exportable as SOC 2 / HIPAA / GDPR-formatted JSONL or CSV. Retention configurable up to 7 years on Enterprise.
Sensitive field redaction
Configure per-domain redaction rules: SSN, credit card numbers, bank account numbers, healthcare identifiers. Redaction happens at snapshot time — operators and audit log never see the raw value, only the masked one.
Allowed domains
Each agent declares its domain allowlist. BatonPass refuses handoffs from any other domain. Prevents agent compromise from triggering handoffs on attacker-controlled pages.
Compliance posture
SOC 2 Type II in audit (target Q3 2026). HIPAA-ready architecture (BAA available on Enterprise). GDPR Article 17 deletion API. CCPA-compliant data subject access.