Skip to content

// security

Infrastructure

Applies to

Product: Cloud · Audience: Security / Compliance reviewer

Which infrastructure the Cloud runs on and who is involved. In short: basebox Cloud runs on basebox's own server, provided by FAST LTA and located in the Noris data center in Munich. Platform and language model both run on this server. No third party processes data. basebox operates the server and is your processor.

The setup

Layer What Where / by whom
Hardware FAST LTA server Provided to basebox by FAST LTA
Location Data center, power, connectivity Noris, Munich – Noris processes no data
Operating system, Kubernetes Hardening, patching, updates basebox
basebox platform frontend, AISRV, storesrv, Keycloak, PostgreSQL (CloudNativePG), ingress/TLS basebox, on the server
Service models ragsrv, ragsrv-support, OCR, speech-to-text basebox, on the server
Language model (inference) Local on the server basebox, on the same server
Connector services Calculator, web search, e-mail, others by arrangement basebox provides; you configure
Application Organization, users, apps, knowledge bases, policies, audit You

Several customer organizations share this server, each in an isolated environment (Isolation). The components and their communication paths are the same as on basebox Server – basebox components.

What this means for the assessment

  • No external model provider. The language model runs on the same server as the platform; prompts go to no third party (Model providers).
  • No hyperscaler in the chain. Noris adds a data center operator that provides space, power and connectivity but processes no data. Third-country questions arise only from services you enable yourself – web search provider, connector target systems.
  • One processor. basebox operates the server and processes as a processor; the DPA is at basebox.ai/de/legal#data.
  • Physical access lies with a third party. As data center operator, Noris has physical access to the site. Encrypted disks are therefore an important control (Encryption).
  • Same software as Server. Security properties of the application – role model, connector gate, audit log, web search controls – are identical; you can verify them in the Demo with test data.

Distinction from the Demo

The Demo is a separate setup: platform at Hetzner, language model Claude via Google Vertex AI. It shares no infrastructure with the Cloud. Statements about the Demo can therefore not be transferred to the Cloud and vice versa (Demo).

What basebox tells you

For contract negotiation, as far as not yet answered here:

  • Certifications of the Noris data center and its physical access controls
  • Redundancy of power, cooling and network
  • Network architecture between customer environments (Isolation)
  • Fixed egress addresses of the Cloud for your firewall (Network connectivity)

Contact: datenschutz@basebox.ai.

Operation

basebox applies updates; changes are in the Changelog. Security updates are prioritized; in case of known systemic risks or security-relevant incidents basebox informs affected customers without delay (Compliance document). Before every release the software goes through static code analysis, dependency scan, CVE check, unit tests, test installation and manual QA (Infrastructure policy). Maintenance windows and availability commitments are regulated by your contract.

Next step: Administrative access