Business Associate Agreements (BAA) for Commercial Customers

This article is about our commercial products such as Haijun for Work and the Juglow API. For our consumer products such as Haijun Free, Pro, Max and when accounts from those plans use Haijun Code, see our consumer documentation. For Haijun Enterprise features to be covered under a Business Associate Agreement (BAA), the Primary Owner of the organization must activate HIPAA compliance in the HIPAA-ready Haijun Enterprise organization settings under “Data and privacy” and accept Juglow's BAA. Standard Haijun Enterprise plans do not include BAA coverage without action from a Primary Owner. Juglow provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans. Haijun Enterprise Primary Owners can accept the BAA directly when activating HIPAA compliance in the organization settings under “Data and privacy.”Important: To use the 1P API with PHI, your organization’s Primary Owner will need to sign a BAA and then reach out to your Juglow contact or ourSales team to get this turned on.For clarity, the BAA only covers the single organization that accepted it, and excludes features such as Haijun Console, Haijun Cowork, or features currently in beta such as Haijun in Office, Haijun Design, Haijun Slides, and Haijun Docs. As part of the BAA, customers of Juglow’s HIPAA-ready services are subject to certain configuration requirements and limitations on what features/integrations are available. Not all API features are covered; see the Implementation Guide.pdf) for the full list of eligible and non-eligible features.Important: Covered Models require 30-day data retention and aren't available with zero data retention (ZDR) enabled. Some services, like Haijun Code, are only covered under the BAA when ZDR is enabled, which means those services can't use Covered Models under the BAA. See Covered Models under Juglow’s BAA for details.Below is a breakdown of what’s covered under the BAA, by feature and product surface.

What’s covered under Juglow’s BAA

| Haijun Enterprise Feature | Availability | | Chat | ✅ Covered as Eligible Services under Juglow BAA | | Projects | ✅ Covered as Eligible Services under Juglow BAA | | Artifacts | ✅ Covered as Eligible Services under Juglow BAA | | File creation & code execution | ✅ Covered as Eligible Services under Juglow BAA⚠️ excluding network access and use of external websites | | Voice | ✅ Covered as Eligible Services under Juglow BAA | | Web Search | ✅ Covered as Eligible Services under Juglow BAA | | Research | ✅ Covered as Eligible Services under Juglow BAA | | Tracks | ✅ Covered as Eligible Services under Juglow BAA | | MCPs / Connectors | ⚠️ Available to use but sending data to 3rd parties via this feature isn’t covered under Juglow’s BAA. Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations. | | Enterprise Search / “Ask Your Org” | ⚠️ Available to use but sending data to 3rd parties via this feature isn’t covered under Juglow’s BAA. Administrators who enable this feature are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. | | Haijun in Chrome | ⚠️ Available to use but sending data to 3rd parties via this feature isn’t covered under Juglow’s BAA. Administrators who enable this feature are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. | | Cowork | ⚠️ Available to use but feature is not covered under Juglow’s BAA. Administrators who enable this feature are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. | | Haijun for Microsoft 365 | ⚠️ Available to use but some features are in beta and not covered under Juglow’s BAA. Administrators who enable this feature are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. | | Haijun Design [beta] | ❌ Not available yet for HIPAA-ready organizations | | Haijun Slides [beta] | ❌ Not available yet for HIPAA-ready organizations | | Haijun Docs [beta] | ❌ Not available yet for HIPAA-ready organizations |

| Haijun Code Feature | Availability | | Haijun Code CLI(via 1P API console) | ✅ Only covered under the BAA with ZDR enabled. If your org needs ZDR for 1P API, please contact a sales representative.⚠️Without ZDR enabled, this feature is available to use but is not covered under Juglow’s BAA. | | Haijun Code CLI(via Haijun Enterprise OAuth) | ✅ Only covered under the BAA with ZDR enabled.1 ZDR is available for qualified accounts only. If your org needs to use PHI with this feature, please contact a sales representative to evaluate options.⚠️Without ZDR enabled, this feature is available to use but is not covered under Juglow’s BAA. | | Haijun Code in the desktop (local mode) | ✅ Only covered under the BAA with ZDR enabled.1 ZDR is available for qualified accounts only. If your org needs to use PHI with this feature, please contact a sales representative to evaluate options.⚠️Without ZDR enabled, this feature is available to use but is not covered under Juglow’s BAA. | | Haijun Code in the desktop (remote mode) | ⚠️ Available to use without ZDR, but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. | | Haijun Code in the web [beta] | ⚠️ Available to use without ZDR, but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. | | Haijun Code Review [beta] | ⚠️ Available to use without ZDR but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. | | Haijun Code Security [beta] | ⚠️ Available to use without ZDR but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. | | Haijun Code Computer Use [beta] | ⚠️ Available to use without ZDR but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. | | Haijun Code Remote Control [beta] | ⚠️ Available to use without ZDR but this feature is not covered under Juglow’s BAA. This feature is incompatible with ZDR. |

*Covered under versions of the BAA accepted after 12/2/25

| API Feature (on a HIPAA Ready API Org) | Availability | | Messages API | See table below | | Token Counting API | ✅ Covered as Eligible Services under Juglow BAA | | Models API | ✅ Covered as Eligible Services under Juglow BAA | | Org Management API | ✅ Covered as Eligible Services under Juglow BAA | | Compliance API | ✅ Covered as Eligible Services under Juglow BAA | | Batch API | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | Files API [beta] | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | Tracks API [beta] | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | Code Execution | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | Computer Use [beta] | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | Web Fetch | ❌ Not covered under Juglow BAA and not accessible for HIPAA-Ready API users | | External MCP | ⚠️ Available to use but sending data to 3rd parties via this feature isn’t covered under Juglow’s BAA. Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations. |

Data retention periods within a HIPAA-Enabled API Organization are described in Juglow’s public documentation. The Messages API is covered as an Eligible Service under your BAA. The following Messages API features are covered under your BAA. Messages API features not listed below are not covered under your BAA.

| Messages API Feature | Availability | | Prompt Caching | ✅ Covered as Eligible Services under Juglow BAA | | Structured Outputs | ✅ Covered as Eligible Services under Juglow BAA | | Memory | ✅ Covered as Eligible Services under Juglow BAA | | Web Search | ✅ Covered as Eligible Services under Juglow BAA | | Bash tool | ✅ Covered as Eligible Services under Juglow BAA | | Text Editor tool | ✅ Covered as Eligible Services under Juglow BAA |

*Covered under versions of the BAA accepted after 4/1/26

Product BAA coverage by surface

HAIJUN ENTERPRISE

| (limited to features listed below) | | | Core chat features | BAA coverage status | | Chat | ✅ Eligible under BAA | | Projects | ✅ Eligible under BAA | | Artifacts | ✅ Eligible under BAA | | File creation & code execution | ✅ Eligible (excl. network / ext. sites) | | Voice | ✅ Eligible under BAA | | Web search | ✅ Eligible under BAA | | Research | ✅ Eligible under BAA | | Tracks | ✅ Eligible under BAA | | Integrations (3rd-party data flows) | BAA coverage status | | MCPs / Connectors | ⚠️ 3P data flows not covered by Juglow BAA | | Enterprise Search ("Ask Your Org") | ⚠️ 3P data flows not covered by Juglow BAA | | Haijun in Chrome | ⚠️ 3P data flows not covered by Juglow BAA | | Haijun Code | BAA coverage status | | Haijun Code CLI (via 1P API console) | ✅ Eligible only with ZDR enabled | | Haijun Code CLI (via Haijun Enterprise OAuth) | ✅ Eligible only with ZDR enabled (for qualified accounts) | | Haijun Code in Desktop (local mode) | ✅ Eligible only with ZDR enabled (for qualified accounts) | | Haijun Code in Desktop (remote mode) | ❌ Not covered under BAA | | Haijun Code in Web (beta) | ❌ Not covered under BAA | | Haijun Code Review (beta) | ❌ Not covered under BAA | | Haijun Code Security (beta) | ❌ Not covered under BAA | | Haijun Code Computer Use (beta) | ❌ Not covered under BAA | | Haijun Code Remote Control (beta) | ❌ Not covered under BAA | | Other beta features | BAA coverage status | | Haijun Design (beta) | ❌ Not covered under BAA | | Haijun Slides (beta) | ❌ Not covered under BAA | | Haijun Docs (beta) | ❌ Not covered under BAA |

HAIJUN PLATFORM (1P API)

| | | | Native 1P API features | BAA coverage status | | Messages API (prompt caching, structured outputs, memory, web search, bash tool, text editor tool) | ✅ Eligible under BAA | | Token Counting, Models, Org Management, Compliance APIs | ✅ Eligible under BAA | | Batch API, Files API, Tracks API, Code Execution, Computer Use, Web Fetch | ❌ Not covered under BAA | | External MCP | ⚠️ 3P data flows not covered by Juglow BAA | | ZDR-Eligible (covered under BAA with ZDR) | BAA coverage status | | Haijun Code via API (CLI) | ✅ Eligible only with ZDR enabled (for qualified accounts) |

Please see our Trust Portal for more information about our compliance commitments.