Licensed to be used in conjunction with basebox, only.
// security
ISO 27001
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer
basebox's ISO 27001 certification: what it means, what it covers, and what it means for Cloud and Server customers. basebox describes itself as ISO 27001 certified (basebox: the compliant AI platform). Certificate, scope statement and certification body are available on request for your vendor assessment.
What an ISO 27001 certification says – and what not
Says: basebox runs an information security management system (ISMS) that has been audited by an independent body: risk management, policies, responsibilities, controls from Annex A, internal audits, continual improvement – within the defined scope.
Does not say: that a particular technical property of the software exists (for example encryption at rest), that your installation is securely configured, or that your own organization meets requirements. The certification describes the supplier, not your deployment.
What it means per deployment model
| Meaning of basebox's certification | |
|---|---|
| basebox Cloud | Directly relevant: basebox operates the infrastructure and processes as a processor. The ISMS covers – subject to the scope statement – the operational processes: access control for operations staff, change management, incident handling, supplier management (data center). For your vendor assessment the certificate is the central evidence. |
| basebox Server, self-operated | Relevant for the software supply chain: secure development, release process, handling of vulnerabilities, communication of security updates. The operation of your server sits in your own ISMS. |
| basebox Server, operated by basebox | Both: software supply chain and the operational processes basebox works with via the maintenance access. |
| Demo | Irrelevant to your assessment – no real data. |
Controls you find in basebox
Mapping of typical audit questions (ISO 27001:2022, Annex A) to what basebox delivers – as a help for your own assessment, not as a statement about the certification scope:
| Topic | What basebox delivers | Page |
|---|---|---|
| Access control (A.5.15–5.18, A.8.2–8.5) | Role model, groups, OIDC/LDAP, API keys, connector gate with per-user credentials | Roles & permissions · Connectors |
| Logging and monitoring (A.8.15–8.16) | Audit log with retention, detail level, export; metrics and logs on Server | Audit & logging · Monitoring |
| Cryptography (A.8.24) | TLS on all paths; storage encryption at the storage layer; application-level encryption at rest openly named as not implemented | Encryption |
| Secure development (A.8.25–8.29) | Static analysis, dependency scan, CVE check, tests, manual QA, four-eyes principle | Infrastructure policy |
| Change management (A.8.32) | Release notes and changelog per version; maintenance windows with announcement, backup, report | Updates · Remote maintenance |
| Vulnerability management (A.8.8) | Prioritized security updates, announcement by e-mail | Compliance document |
| Incident management (A.5.24–5.28) | Immediate information of affected customers; reporting channel datenschutz@basebox.ai | GDPR |
| Backup (A.8.13) | CloudNativePG backups, dumps; in the Cloud by basebox | Backup |
| Supplier relationships (A.5.19–5.23) | Model register for the model supply chain; image signatures in preparation | Model register |
| Privacy (A.5.34) | Roles, DPA, data subject rights | GDPR |
| Remote access (A.6.7, A.8.1) | PAM/VPN, time-limited, approved, logged, revocable | Remote maintenance |
For the review
- Request certificate, scope statement and validity from datenschutz@basebox.ai; check whether the scope covers the processes relevant to you (Cloud operation or software development).
- For Cloud, additionally request the data center's certification (Infrastructure).
- Your own ISMS: record your basebox installation as an asset, compare the controls above with your configuration, track open points (storage encryption, policies) as measures.
- In the supplier audit ask about: handling of vulnerability reports, response times, subcontractors.
Next step: NIS2