Licensed to be used in conjunction with basebox, only.
// security
Compliance
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer
Regulatory frameworks and how basebox relates to them: GDPR, ISO 27001, NIS2 and the EU AI Act. The EU AI Act material used to sit under the developer documentation; now it lives here. These pages do not replace legal advice – they say what basebox delivers technically and organizationally, which role basebox has per framework and what stays with the customer.
The frameworks
| Framework | basebox's role | What sits with the customer | Page |
|---|---|---|---|
| GDPR | Cloud: processor with DPA · Server: without access not a processor; under an operations contract contractual · Demo: no real data | Controller; record of processing, legal basis, data subject rights, DPIA where applicable | GDPR |
| ISO 27001 | basebox is ISO 27001 certified; scope and certificate on request | Own ISMS; assess basebox as a supplier | ISO 27001 |
| NIS2 | Supplier/service provider of an essential or important entity | Duties of the entity: risk management, supply chain, reporting | NIS2 |
| EU AI Act | Supplier/infrastructure provider, not a provider (no own models, quantization only) | Deployer: risk classification, human oversight, transparency, AI literacy | Compliance document |
The EU AI Act package
Five versioned documents (version 1.0, as of October 2025, referring to basebox Server):
- Compliance – legal classification, duties of basebox and the customer, model responsibility, reporting duties
- Infrastructure policy – technical and organizational measures with a status per measure (implemented / partial / planned)
- Model register – source, licence, version, quantization, review status of the provided models
- Safety notice – residual risks, recommendations for operators, incident reporting
- Disclaimer – liability framework
The pages under Security & Compliance are the continuously maintained description; where they differ, the versioned package governs for contractual purposes. Where this documentation knows of a difference – for example the audit export that exists by now but is still listed as planned in the infrastructure policy – it is named on the respective page.
What recurs in every review
- Roles: basebox provides software and, where applicable, operation; the customer determines purpose, data and use. That applies equally to GDPR (controller), EU AI Act (deployer) and NIS2 (entity) – Shared responsibility.
- Data processing boundary: Cloud = your isolated environment in the basebox data center; Server = your network – Data flows.
- Controls with status: basebox openly names what is implemented and what is not (encryption at rest, image signatures, kill switch, manual pre-review) – Server.
- Evidence: audit log and export, release notes, model register, maintenance reports, DPA.
Contact
Data protection and compliance questions, DPA, certificates: datenschutz@basebox.ai · basebox GmbH, Bahnhofplatz 3, 86919 Utting am Ammersee, Germany.
Next step: GDPR