Licensed to be used in conjunction with basebox, only.
// installation
Operation by basebox
Applies to
Product: Server · Operation: by basebox · Audience: IT management · Administrator · Security reviewer
When basebox has been commissioned to install and/or operate: access path (PAM/VPN or as agreed), limits of the engagement, how maintenance windows run and what stays with the customer. Operation by basebox is a separate engagement in addition to the software licence; its scope is defined per project.
What basebox takes on in the operations engagement
Depending on scope – the table is the template for the contract:
| Area | Typically in scope | Note |
|---|---|---|
| Operating system, NVIDIA drivers, Kubernetes | ✔, if agreed | Updates in agreed maintenance windows |
| basebox installation and updates | ✔ | Release planning with you; backup before every upgrade |
| Service models, inference | Per project scope | Model changes on request of the administrators |
| Monitoring, alerting | ✔, if agreed | What is monitored is in the contract |
| Backups and restore | ✔, if agreed | Define target, frequency, retention, restore tests |
| Network | Shared | Customer network with the customer; access path with basebox |
| Connector workloads | ✔, if agreed | Endpoints via Helm; making target systems in the customer network reachable remains a customer task |
| Physical hardware, data center | Only with hosting at basebox | Otherwise customer |
What is not in scope lies with you – and the table under Responsibilities is built to assign every row unambiguously.
What stays with the customer – always
- Application administration: users, groups, roles, model selection, apps, knowledge bases, connector enablement, policies, audit. basebox operates the infrastructure, not your organisation.
- Data: documents, chats, knowledge bases – responsibility in the data protection sense remains with you.
- Approvals: maintenance windows, opening access, sign-off of changes.
- Contact person: one named person who approves and signs off.
The access path
basebox accesses via a controlled, agreed path – typically privileged access management (PAM) and/or VPN:
- Time-limited: access is opened for the maintenance purpose and disabled afterwards.
- Approved by the customer: you open the access – or have an approval process that basebox uses.
- Logged: sessions are recorded according to your PAM's capabilities; basebox actions in the application appear in the audit log.
- Revocable: you can withdraw access at any time.
What exactly is logged, who approves and how revocation works: Remote maintenance. A server hosted at basebox changes nothing about this – access to the software stack follows the same model.
How a maintenance window runs
- Announcement by basebox: what, why (release notes), when, expected impact (downtime, inference restarts).
- Approval by your contact person; the access path is opened.
- Backup of the databases before changes; mandatory for upgrades (migrations are forward-only).
- Execution with rendering before applying; acceptance checks per Validate installation in abbreviated form.
- Report to you: what was changed, new versions (manifest), open items.
- Close access.
Security updates may follow a shorter procedure with pre-agreed standard windows – that belongs in the contract.
Information flows
| From basebox to you | From you to basebox |
|---|---|
| Release notes and changelog per version, announcement of security updates | Approvals for maintenance windows and access |
| Maintenance reports with manifest | Changes in your network that affect operations (DNS, firewall, certificates) |
| Monitoring alerts, if agreed | Requests from the administrators: new model, new connector, capacity |
| Immediate notification of systemic risks or security-relevant incidents | Reporting of incidents and observations (datenschutz@basebox.ai) |
Limits of the engagement
- basebox does not manage your users, apps or data and does not see your users' connector credentials (stored write-only).
- basebox does not operate your data center, your network or your target systems – except the physical side with hosting.
- Changes to your firewall, DNS, certificates or directory remain with you, even when basebox requests them.
- What the contract does not name is not included. Clarify beforehand when in doubt.
If you take over operations later
A handover from basebox to your IT includes manifest, values files (without secrets), credentials, acceptance record, backup evidence and termination of basebox's access – the checklist is under Customer-managed operations → Handover.
For security reviewers
The security posture with operation by basebox – access path, logging, data access – is described under Security & Compliance → Remote maintenance and Shared responsibility. The EU AI Act compliance package records that maintenance access takes place exclusively via VPN/PAM, time-limited and approved by the customer (Infra Policy).
Next step: Monitoring