Skip to content

// security

ISO 27001

Applies to

Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer

basebox's ISO 27001 certification: what it means, what it covers, and what it means for Cloud and Server customers. basebox describes itself as ISO 27001 certified (basebox: the compliant AI platform). Certificate, scope statement and certification body are available on request for your vendor assessment.

What an ISO 27001 certification says – and what not

Says: basebox runs an information security management system (ISMS) that has been audited by an independent body: risk management, policies, responsibilities, controls from Annex A, internal audits, continual improvement – within the defined scope.

Does not say: that a particular technical property of the software exists (for example encryption at rest), that your installation is securely configured, or that your own organization meets requirements. The certification describes the supplier, not your deployment.

What it means per deployment model

Meaning of basebox's certification
basebox Cloud Directly relevant: basebox operates the infrastructure and processes as a processor. The ISMS covers – subject to the scope statement – the operational processes: access control for operations staff, change management, incident handling, supplier management (data center). For your vendor assessment the certificate is the central evidence.
basebox Server, self-operated Relevant for the software supply chain: secure development, release process, handling of vulnerabilities, communication of security updates. The operation of your server sits in your own ISMS.
basebox Server, operated by basebox Both: software supply chain and the operational processes basebox works with via the maintenance access.
Demo Irrelevant to your assessment – no real data.

Controls you find in basebox

Mapping of typical audit questions (ISO 27001:2022, Annex A) to what basebox delivers – as a help for your own assessment, not as a statement about the certification scope:

Topic What basebox delivers Page
Access control (A.5.15–5.18, A.8.2–8.5) Role model, groups, OIDC/LDAP, API keys, connector gate with per-user credentials Roles & permissions · Connectors
Logging and monitoring (A.8.15–8.16) Audit log with retention, detail level, export; metrics and logs on Server Audit & logging · Monitoring
Cryptography (A.8.24) TLS on all paths; storage encryption at the storage layer; application-level encryption at rest openly named as not implemented Encryption
Secure development (A.8.25–8.29) Static analysis, dependency scan, CVE check, tests, manual QA, four-eyes principle Infrastructure policy
Change management (A.8.32) Release notes and changelog per version; maintenance windows with announcement, backup, report Updates · Remote maintenance
Vulnerability management (A.8.8) Prioritized security updates, announcement by e-mail Compliance document
Incident management (A.5.24–5.28) Immediate information of affected customers; reporting channel datenschutz@basebox.ai GDPR
Backup (A.8.13) CloudNativePG backups, dumps; in the Cloud by basebox Backup
Supplier relationships (A.5.19–5.23) Model register for the model supply chain; image signatures in preparation Model register
Privacy (A.5.34) Roles, DPA, data subject rights GDPR
Remote access (A.6.7, A.8.1) PAM/VPN, time-limited, approved, logged, revocable Remote maintenance

For the review

  1. Request certificate, scope statement and validity from datenschutz@basebox.ai; check whether the scope covers the processes relevant to you (Cloud operation or software development).
  2. For Cloud, additionally request the data center's certification (Infrastructure).
  3. Your own ISMS: record your basebox installation as an asset, compare the controls above with your configuration, track open points (storage encryption, policies) as measures.
  4. In the supplier audit ask about: handling of vulnerability reports, response times, subcontractors.

Next step: NIS2