Thanks @shanedelierrr for that detailed info. It all makes sense.
Even though most of our websites have already been updated to WPCore 7.0.2, I tend to agree with our host provider we should leave the hard block on REST batch/v1 in place, rather than whitelist it.
I guess I’ll have to wait until the devs can find an alternative way to save the Kadence Security settings and have to use another plugin for now.