Baidu AI Cloud Object Storage (BOS) Trusted Cloud Certification
1. Service scope
The Baidu AI Cloud Object Storage (BOS) provides a stable, secure, efficient, and highly scalable storage service. It supports various data types, including text, multimedia, and binary files, with a maximum single file size of 48.8 TB.
2. Service availability
2.1. Definition
Service period: One service period equals one calendar month.
Failed requests: BOS regards requests with an HTTP status code of 5XX and normal user requests that fail to reach the BOS server due to BOS service failures as failed requests, but does not include the following types of requests:
(1) Failed requests processed asynchronously by the real server for region replication and lifecycle management;
(2) Failed requests generated from obtaining the bucket list;
(3) Failed requests or service unavailable situations caused by reasonable upgrades, changes, outages by BOS service;
(4) Requests restricted by BOS caused by hacker attacks on user applications;
(5) Requests from abroad to domestic BOS service.
Valid requests: BOS regards requests received by the BOS server-side as valid requests, but does not include the following types of requests:
(1) Requests and requests with arrears that have not passed BOS identity and failed authentication;
(2) Failed requests initiated for asynchronous processing of the real server for region replication and lifecycle management;
(3) Requests initiated for obtaining the bucket list;
(4) Requests initiated due to hacker attacks on user applications.
Error rate per 5 minutes: This bucket is calculate with a granularity of 5 minutes according to the following formula:

Monthly service fee: The service fee incurred by users in a specific bucket within a calendar month. If a user deduct the fees through prepaid storage package, the deducted capacity portion will be charged according to postpay.
2.2 Calculation formula of service availability
The availability is calculated by service period, with one service period being a natural month. The service unit measured by the BOS service is user's bucket. Service availability is calculated by dividing the sum of error rates per 5 minutes within the service period by the total number within 5 minutes within the service period to derive the average value of error rate per 5 minutes, according to the formula below:

2.3 Service availability commitment
| Storage class | Service availability |
|---|---|
| Standard storage | 99.95% |
| Infrequent access storage | 99.95% |
| Cold storage | 99.95% |
| Archive storage | 99.00% |
If BOS fails to meet the stated availability commitments, customers are eligible to apply for compensation.
Exemption clauses of service provider:
The compensation does not cover service unavailability caused by the following reasons:
(1) Scheduled maintenance of Baidu AI Cloud that has been notified to users, including reasonable upgrades, changes, outages, migrations, repairs, and simulated failure drills;
(2) Unavailability caused by network, device failures or configuration adjustments beyond the Baidu AI Cloud equipment;
(3) Errors caused by user content violations or other reasons leading to domain name bans;
(4) Unavailability caused by hacker attacks on user applications or data;
(5) Unavailability caused by data, credentials or password loss/leakage due to user maintenance negligence or improper confidentiality;
(6) User negligence or authorized operations;
(7) Unavailability caused by client non-compliance with Baidu AI Cloud product documentation or recommendations, including operations on BOS via console/API/CLI;
(8) Errors caused by customer-installed software or third-party software/configuration not directly operated by Baidu AI Cloud;
(9) Force majeure or unforeseen events;
(10) Unavailability caused by other reasons outside Baidu AI Cloud's scope.
3. Data persistence
A service period is defined as a calendar month; partial months are counted as full months. The persistence commitment for storage during the service period is 99.999999999% (11 nines). This means that for every 100 billion files stored, at most only one file could be lost per month.
4. Data destructibility
4.1. When a user actively deletes data or needs to destruct data after the service period expires, Baidu AI Cloud will automatically clear the corresponding disk and memory data on the physical server, making the data unrecoverable, so please operate with caution. Agreed deletion deadline is upon service expiration, which complies with legal requirements.
4.2. Before the equipment used by Baidu AI Cloud BOS instances are scrapped, discarded, outsourced for repair or resold, Baidu AI Cloud will perform degaussing operations on their physical disks. The entire degaussing process will be monitored by video and corresponding records will be retained for a long time. Baidu AI Cloud regularly audits disk erasure records and video evidence to meet security compliance requirements.
5. Data migratability
5.1. [Immigration-in] When users enable Baidu AI Cloud BOS services, provides tools such as upload API, data transmission service to facilitate rapid data migration.
5.2. [Migration-out] When using Baidu AI Cloud BOS services, users can delete data or migrate data out as needed. Baidu AI Cloud Object Storage provides lists for retrieving all files and download APIs for you to perform download and migration for data.
6. Data privacy
The data you process, store, upload, download, or distribute via Baidu AI Cloud services remains entirely your own business data. As a neutral technical service provider, Baidu AI Cloud strictly follows your directives. Except for providing agreed-upon technical support for troubleshooting and issue resolution, abiding by specific product rules, fulfilling your explicit requirements, or complying with legal and regulatory obligations, we will not access, use, or disclose your business data without authorization. All operational and maintenance activities at Baidu AI Cloud are logged and retained.
7. Data transparency right
You can query data region and bucket details via the product console and APIs. Choose regions to store data based on your needs. North China-Beijing, South China-Guangzhou, and East China-Suzhou data centers are located in Beijing, Baoding, Guangzhou, and Suzhou, respectively. Data stored in these regions is redundantly saved within the data centers using erasure coding technology. Users can back up data using the self-selected data synchronization feature. Backup data can be saved in the same region or other regions for disaster recovery purposes. Except when required by local laws, regulations, or government auditing needs, user data, applications, and activity logs will not be shared with third parties. User data is not stored in overseas data centers and is not used for international business or analysis. All data centers comply with local legal requirements related to data centers.
8. Data auditability
In compliance with applicable laws and regulations, Baidu AI Cloud may provide object storage-related information to meet government regulatory or security investigation requirements. This may include the operation logs of critical components, records of O&M personnel activities, and user operation logs, following proper and complete procedures.
9. Service functions
The Baidu AI Cloud Object Storage (BOS) offers a stable, secure, efficient, and highly scalable storage service, supporting various types of data storage such as text, multimedia, and binary, with a maximum single file size of 48.8 TB. It also provides basic functionalities like uploading, downloading, deleting, copying, management, and advanced features such as server-side data encryption, fine- and coarse-grained access control, automatic data replication, and processing of data (images, videos), among others. For detailed feature introductions and operations, please refer to the user manuals. Baidu AI Cloud will promptly notify users of any updates or changes to services and inform them of necessary adjustments through online notifications, emails, phone calls, and other communication methods.
10. Service resource allocation capability
Baidu AI Cloud promises users that the activation of Baidu AI Cloud Object Storage can be completed within minutes. There is no limit to the capacity of a single storage space or file and the number of buckets is limited to 100 per user. If the user limit is exceeded and expansion is needed, please contact Baidu AI Cloud customer service to query the completion time.
11. Fault recovery capability
Baidu AI Cloud ensures the fault recovery capability of its object storage services through comprehensive fault management systems, including fault monitoring, rapid identification, self-healing, and automatic notification. Recovery methods include online migration, downgrade recovery, and more. Additionally, Baidu AI Cloud's professional service team provides 24/7 support services.
12. Network access performance
After activating the Baidu AI Cloud Object Storage (BOS) service and creating buckets, BOS sets a default public network bandwidth limit of 10 Gbit/s and a default intranet bandwidth limit of 50 Gbit/s for each bucket.
13. Service billing accuracy
Baidu AI Cloud Object Storage (BOS) offers two billing methods: pay-as-you-go and prepaid resource packages. Pay-as-you-go is a postpaid method and serves as the primary billing option, billed by the minute with hourly invoices. The prepaid option includes a variety of resource packages designed around billing items that can offset fees incurred. The service provides an accurate and transparent metering and billing system, which calculates fees based on actual usage. Additionally, monthly and daily consumption reports are available according to user needs, and original billing logs are retained for at least three years by default for audit purposes.
14. Service change, termination terms and service availability compensation terms
Baidu AI Cloud will make necessary changes or terminations for product service functions based on the actual situation and regulatory requirements if the commitment needs any necessary changes or terminations due to changes in the external environments such as laws, regulations and regulatory requirements. Baidu AI Cloud will negotiate with you to make proper transitional arrangement for the service changes or terminations. For details, please refer to Contract Change and Termination.
14.1. Service availability compensation
For detailed introductions to service availability compensation, please refer to BOS Service Level Agreement (SLA).
14.2. Clauses of users constraints
For the clauses of users constraints, refer to the related provisions of the "User Rights and Obligations" section in the Baidu AI Cloud User Service Agreement.
14.3.Exemption clauses of service provider
For the exemption clauses of service provider, refer to the related provisions of the "Disclaimer" in the Baidu AI Cloud User Service Agreement.
15. Miscellaneous
You acknowledge and agree that trusted cloud certification is conducted annually. Therefore, Baidu AI Cloud will annually update and adjust its trusted cloud documentation in accordance with certification authority requirements and changes to Baidu AI Cloud products.
