Licensed to be used in conjunction with basebox, only.
// security
Security & Compliance
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer
For security officers, data protection officers and compliance reviewers. The section follows the product model: what applies to Demo, Cloud and Server is kept separate, and a customer-owned server hosted at basebox sits under Server security – not under Cloud. Where a statement is not yet substantiated, that is said explicitly; nothing on these pages is marketing.
In this section
- Deployment models – Demo, Cloud, Server and the model of shared responsibility
- Data & architecture – flows, storage, encryption, retention, deletion
- Cloud security – isolation, infrastructure, administrative access, backup
- Server security – dedicated hardware, customer data center, hosting at basebox, remote maintenance, air-gapped operation
- External services – model providers, web search, connectors
- Audit & logging
- Compliance – GDPR, ISO 27001, NIS2, EU AI Act
The short version
| Question | One-sentence answer | Details |
|---|---|---|
| Do chats and documents leave the environment? | In Cloud and Server, in normal operation no; the deliberate, administrator-controlled exceptions are web search and connectors. In the Demo every model request goes to Google Vertex AI | Data flows |
| Where do the language models run? | In the Cloud on basebox's own server at Noris in Munich, on Server on customer-controlled hardware – in both cases without an external model provider. Only the Demo uses Claude via Google Vertex AI | Model providers |
| Who is the controller under data protection law? | Always the customer; in the Cloud basebox is a processor with a DPA, on a self-operated server basebox has no access | GDPR |
| Is everything encrypted? | In transit yes (TLS); at rest the application itself does not encrypt today – that is done by the storage layer | Encryption |
| What does the audit log record? | By default actions, not conversation content; content only on explicit setting, then with a visible notice in the chat | Audit & logging |
| How does basebox get onto a server? | Only when commissioned, via PAM/VPN, time-limited, approved by the customer and revocable | Remote maintenance |
| Does it work without internet? | Yes – basebox Server can run air-gapped; web search and online model download are then unavailable | Air-gapped environments |
How to read these pages
- Every page carries an Applies to box at the top. Check first whether your deployment is meant – statements about the Cloud do not apply to a server and vice versa.
- Never generalize Demo statements. The Demo is a test environment with possibly different infrastructure.
- Where this documentation cannot yet substantiate a statement, it points to the way to clarification – usually datenschutz@basebox.ai for data protection and compliance questions and support@basebox.ai for technical ones.
- The EU AI Act compliance package – Compliance, Infrastructure policy, Model register, Safety notice, Disclaimer – refers to basebox Server and is dated October 2025. The pages here are the continuously maintained description; where they differ, the versioned package governs for contractual purposes.
What to take into a review
When you describe basebox in a data protection impact assessment, a security concept or a vendor assessment, these pages are usually sufficient: Deployment model or Server, Data flows, Storage, Encryption, Audit & logging, Shared responsibility and GDPR. For the web search connector there is additionally the Introduction to web search security and, on request, the full policy.
Next step: Deployment model: Demo