Licensed to be used in conjunction with basebox, only.
// security
Administrative access
Applies to
Product: Cloud · Audience: Security / Compliance reviewer
Who at basebox can access what in a Cloud environment, and how that access is controlled and logged. The dividing line is clear: basebox operates the infrastructure, you administer the application. That basebox operates the platform does not make basebox the administrator of your users, apps or data.
Two kinds of administration
| basebox operations | Your administrators | |
|---|---|---|
| Role | Platform operator, processor | Application administrators, controller |
| Access to | Data center, Kubernetes, databases, storage, network, inference, Keycloak configuration | Administration of the application: users, roles, groups, models, apps, knowledge bases, connectors, policies, audit log, API keys |
| Purpose | Operation, updates, backups, monitoring, troubleshooting, setup at your request (LDAP, SSO, connectors) | Shaping and controlling your organization |
| Does not see | Your users' connector credentials (stored write-only) | Other users' chats (except via the configured audit recording, then with a notice in the chat); users' connector credentials |
| Does not manage | Your users, apps, data, policies | Infrastructure, versions, model list, Keycloak configuration |
What basebox staff can technically reach
As operator of the infrastructure, basebox operations staff have technical access to the systems your data sits on – databases, media volume, logs. This is the case with every operated service and the reason basebox is a processor in the Cloud and a DPA is concluded. The controls for it:
- Purpose limitation: access only for operation, troubleshooting and setup commissioned by you – never to inspect content.
- Need-to-know: limited group of people with an operations role.
- Logging: administrative access to the infrastructure is logged; actions in your application – for example a setup you commissioned – appear in your audit log.
- Duty to inform: in case of security-relevant incidents basebox informs you without delay.
- No use for own purposes: no training on your content, no passing on to third parties, no analysis of your conversations.
- Framework: ISO 27001 (ISO 27001) and DPA (GDPR).
What you control
You decide who in your organization is an administrator (Users) and see every administrative action in the audit log – including those basebox performs at your request. You can withdraw administrator rights, revoke API keys and change policies at any time. What you cannot do: withdraw basebox's infrastructure access – that is the consequence of the operating model. Whoever needs that control is right with basebox Server.
Setup at your request
Some settings are made by basebox for you because they sit in the Keycloak or platform configuration: LDAP federation, SSO brokering, additional models or connector services, IP restrictions (Customer environment → What you cannot change). Such requests should be made in writing and come from a named person of your organization; basebox confirms the implementation.
For the review
- The DPA names the nature and purpose of access as well as subcontractors.
- Request the permission concept of basebox operations and the logging of administrative access (datenschutz@basebox.ai).
- Review your audit log regularly for administrative actions – including those you commissioned.
- Keep the circle of your own administrators small; every change to roles is in the audit log.
Next step: Backup