Skip to content

// installation

Operation by basebox

Applies to

Product: Server · Operation: by basebox · Audience: IT management · Administrator · Security reviewer

When basebox has been commissioned to install and/or operate: access path (PAM/VPN or as agreed), limits of the engagement, how maintenance windows run and what stays with the customer. Operation by basebox is a separate engagement in addition to the software licence; its scope is defined per project.

What basebox takes on in the operations engagement

Depending on scope – the table is the template for the contract:

Area Typically in scope Note
Operating system, NVIDIA drivers, Kubernetes ✔, if agreed Updates in agreed maintenance windows
basebox installation and updates ✔ Release planning with you; backup before every upgrade
Service models, inference Per project scope Model changes on request of the administrators
Monitoring, alerting ✔, if agreed What is monitored is in the contract
Backups and restore ✔, if agreed Define target, frequency, retention, restore tests
Network Shared Customer network with the customer; access path with basebox
Connector workloads ✔, if agreed Endpoints via Helm; making target systems in the customer network reachable remains a customer task
Physical hardware, data center Only with hosting at basebox Otherwise customer

What is not in scope lies with you – and the table under Responsibilities is built to assign every row unambiguously.

What stays with the customer – always

  • Application administration: users, groups, roles, model selection, apps, knowledge bases, connector enablement, policies, audit. basebox operates the infrastructure, not your organisation.
  • Data: documents, chats, knowledge bases – responsibility in the data protection sense remains with you.
  • Approvals: maintenance windows, opening access, sign-off of changes.
  • Contact person: one named person who approves and signs off.

The access path

basebox accesses via a controlled, agreed path – typically privileged access management (PAM) and/or VPN:

  • Time-limited: access is opened for the maintenance purpose and disabled afterwards.
  • Approved by the customer: you open the access – or have an approval process that basebox uses.
  • Logged: sessions are recorded according to your PAM's capabilities; basebox actions in the application appear in the audit log.
  • Revocable: you can withdraw access at any time.

What exactly is logged, who approves and how revocation works: Remote maintenance. A server hosted at basebox changes nothing about this – access to the software stack follows the same model.

How a maintenance window runs

  1. Announcement by basebox: what, why (release notes), when, expected impact (downtime, inference restarts).
  2. Approval by your contact person; the access path is opened.
  3. Backup of the databases before changes; mandatory for upgrades (migrations are forward-only).
  4. Execution with rendering before applying; acceptance checks per Validate installation in abbreviated form.
  5. Report to you: what was changed, new versions (manifest), open items.
  6. Close access.

Security updates may follow a shorter procedure with pre-agreed standard windows – that belongs in the contract.

Information flows

From basebox to you From you to basebox
Release notes and changelog per version, announcement of security updates Approvals for maintenance windows and access
Maintenance reports with manifest Changes in your network that affect operations (DNS, firewall, certificates)
Monitoring alerts, if agreed Requests from the administrators: new model, new connector, capacity
Immediate notification of systemic risks or security-relevant incidents Reporting of incidents and observations (datenschutz@basebox.ai)

Limits of the engagement

  • basebox does not manage your users, apps or data and does not see your users' connector credentials (stored write-only).
  • basebox does not operate your data center, your network or your target systems – except the physical side with hosting.
  • Changes to your firewall, DNS, certificates or directory remain with you, even when basebox requests them.
  • What the contract does not name is not included. Clarify beforehand when in doubt.

If you take over operations later

A handover from basebox to your IT includes manifest, values files (without secrets), credentials, acceptance record, backup evidence and termination of basebox's access – the checklist is under Customer-managed operations → Handover.

For security reviewers

The security posture with operation by basebox – access path, logging, data access – is described under Security & Compliance → Remote maintenance and Shared responsibility. The EU AI Act compliance package records that maintenance access takes place exclusively via VPN/PAM, time-limited and approved by the customer (Infra Policy).

Next step: Monitoring