Licensed to be used in conjunction with basebox, only.
// security
NIS2
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer
Relevance of NIS2 (Directive (EU) 2022/2555 and its national transposition) for operators of essential and important entities that use basebox – for example hospitals, public authorities, energy and financial companies – and which basebox controls support NIS2 duties. In this relationship basebox itself is a supplier or service provider; the duties fall on the entity that uses basebox. Not legal advice.
Where basebox appears in your NIS2 assessment
| NIS2 duty (Art. 21(2)) | What it means for basebox | Page |
|---|---|---|
| a) Risk analysis and security policies | basebox is a system that potentially processes sensitive content – include it in the risk analysis as an asset with deployment model, data flows and controls | Data flows · Shared responsibility |
| b) Incident handling | basebox informs affected customers without delay in case of security-relevant incidents; your reporting process (24 h early warning, 72 h notification) must include basebox incidents | GDPR → Incidents |
| c) Business continuity, backup, recovery, crisis management | Backups (Cloud by basebox; Server by you), recovery tests, multi-node for resilience | Backup · Backup & restore · Multi-node |
| d) Supply chain security | Assess basebox as a supplier: ISO 27001, release process, vulnerability communication, model supply chain (model register), subcontractors (Cloud data center) | ISO 27001 · Model register |
| e) Security in acquisition, development and maintenance; vulnerability handling | Security tests before release, prioritized security updates with announcement; your patch process on Server; image signatures still in preparation | Infrastructure policy · Updates |
| f) Assessing effectiveness | Audit log and exports as evidence; monitoring on Server | Audit & logging |
| g) Cyber hygiene and training | Usage rules for AI (which data, no confidential information in web searches); AI literacy under the EU AI Act | Policies |
| h) Cryptography and encryption | TLS everywhere; storage encryption at the storage layer; application-level encryption at rest openly named as not implemented | Encryption |
| i) Human resources security, access control, asset management | Role model, groups, OIDC/LDAP, connector gate; server as an asset with manifest | Roles & permissions · Dedicated hardware |
| j) Multi-factor authentication, secured communication | MFA via your identity provider (SSO/OIDC) or Keycloak configuration; TLS; maintenance access via PAM/VPN | OIDC / SSO · Remote maintenance |
Why basebox is relevant for NIS2 entities
Entities under NIS2 often may not hand critical content to external AI services. basebox addresses this with a data processing boundary you know: Server in your own network (also air-gapped) or Cloud on basebox's own server at Noris in Munich, in both cases with the language model on the same server. There is no hyperscaler and no AI API company in the chain whose supply chain security you would additionally have to assess – unless you enable web search or connect an external model service yourself. In the Cloud, include Noris as data center operator in your supply chain assessment (Infrastructure). The Demo is excluded from this: it uses Claude via Google Vertex AI.
What sits with you on Server
On a self-operated server basebox is only the software supplier. The operational NIS2 duties – patching, monitoring, backup, access control, incident detection – you fulfil with your processes; the operations pages under Operations are written for that. Under operation by basebox, the contract regulates which of these duties basebox takes over as a service provider – and you remain responsible towards the supervisory authority.
What you should require from basebox
- Commitment and channel for incident information with a time frame that fits your 24-hour early warning.
- Vulnerability communication: channel, response times, announcement of security updates.
- Supply chain evidence: ISO 27001 certificate, model register, list of subcontractors (Cloud), origin of container images (digests; signatures once available).
- Exit and data return: deletion and export at contract end (Deletion).
For the review
- Record basebox as an asset and as a supplier in your NIS2 register; note the deployment model.
- Compare the controls in the table above with your configuration; track open points as measures.
- Extend your reporting process so that information from basebox feeds into your deadlines.
- Document usage rules for AI as part of the cyber hygiene training.
Next step: EU AI Act → Compliance document