Skip to content

// security

Compliance

Applies to

Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer

Regulatory frameworks and how basebox relates to them: GDPR, ISO 27001, NIS2 and the EU AI Act. The EU AI Act material used to sit under the developer documentation; now it lives here. These pages do not replace legal advice – they say what basebox delivers technically and organizationally, which role basebox has per framework and what stays with the customer.

The frameworks

Framework basebox's role What sits with the customer Page
GDPR Cloud: processor with DPA · Server: without access not a processor; under an operations contract contractual · Demo: no real data Controller; record of processing, legal basis, data subject rights, DPIA where applicable GDPR
ISO 27001 basebox is ISO 27001 certified; scope and certificate on request Own ISMS; assess basebox as a supplier ISO 27001
NIS2 Supplier/service provider of an essential or important entity Duties of the entity: risk management, supply chain, reporting NIS2
EU AI Act Supplier/infrastructure provider, not a provider (no own models, quantization only) Deployer: risk classification, human oversight, transparency, AI literacy Compliance document

The EU AI Act package

Five versioned documents (version 1.0, as of October 2025, referring to basebox Server):

  • Compliance – legal classification, duties of basebox and the customer, model responsibility, reporting duties
  • Infrastructure policy – technical and organizational measures with a status per measure (implemented / partial / planned)
  • Model register – source, licence, version, quantization, review status of the provided models
  • Safety notice – residual risks, recommendations for operators, incident reporting
  • Disclaimer – liability framework

The pages under Security & Compliance are the continuously maintained description; where they differ, the versioned package governs for contractual purposes. Where this documentation knows of a difference – for example the audit export that exists by now but is still listed as planned in the infrastructure policy – it is named on the respective page.

What recurs in every review

  • Roles: basebox provides software and, where applicable, operation; the customer determines purpose, data and use. That applies equally to GDPR (controller), EU AI Act (deployer) and NIS2 (entity) – Shared responsibility.
  • Data processing boundary: Cloud = your isolated environment in the basebox data center; Server = your network – Data flows.
  • Controls with status: basebox openly names what is implemented and what is not (encryption at rest, image signatures, kill switch, manual pre-review) – Server.
  • Evidence: audit log and export, release notes, model register, maintenance reports, DPA.

Contact

Data protection and compliance questions, DPA, certificates: datenschutz@basebox.ai · basebox GmbH, Bahnhofplatz 3, 86919 Utting am Ammersee, Germany.

Next step: GDPR