Skip to content

// security

Cloud

Applies to

Product: Cloud · Audience: Security / Compliance reviewer

Production service with isolated customer environments, operated by basebox. Platform and language model run on basebox's own server, provided by FAST LTA and located in the Noris data center in Munich. No third party processes data, and no customer-owned physical server is involved. This page is the security view of what Deployment models and Customer environment describe technically.

In one paragraph

Your organization receives its own basebox organization at <your-organization>.basebox.ai with its own Keycloak realm, its own users, apps, knowledge bases, settings and its own audit log. The chat history is stored by each user's browser. basebox operates the platform, service models and language model on this server. You administer the application and remain the controller under data protection law; basebox processes as a processor on the basis of a data processing agreement (basebox.ai/de/legal#data). Chats and documents do not leave the Cloud environment in normal operation; you control the deliberate exceptions – web search, connectors, mail.

Security properties

Property Cloud Details
Infrastructure basebox's own server (provided by FAST LTA) in the Noris data center, Munich Infrastructure
Tenant separation Isolated environment per customer organization: own realm, own organization, own subdomain (= the API's X-Realm), own limits Isolation
Operation By basebox – platform, updates, service models, inference, backups, monitoring Administrative access
Application administration By you – users, roles, models, apps, connectors, policies, audit Customer environment
Inference Local on the same server; no external model provider Model providers
Encryption TLS for all user, API and integration paths; encryption at rest at the storage layer Encryption
Backup By basebox Backup
Outbound connections Only web search (when enabled), connectors to your systems, mail; connectors are limited to their target hosts at the MCP gateway Network connectivity
Inbound connections HTTPS 443 from users and API clients; sign-in via your realm or SSO Network connectivity
Data protection role Customer controller, basebox processor with DPA GDPR

What you control

Everything in the administration – and with it all decisions that determine your users' privacy: whether and how conversation content is recorded in the audit log, for how long, whether web search is available and for whom, which connectors reach which systems, whether tools may write, which models users can choose, who is an administrator. The defaults are restrictive (Policies).

What basebox controls

Data center, Kubernetes, storage, the platform's network, versions and update timing, the list of provided models and connector services, the Keycloak configuration (LDAP federation and SSO brokering are set up by basebox at your request). basebox does not manage your users, apps or data and does not see your users' connector credentials.

What leaves the environment

In normal operation nothing – the language model also runs inside the environment. Three deliberate exceptions, all controlled by you:

  1. Web search – the query goes to the configured provider (default: Staan, EU), without user identity and user IP; off by default, consent before the first search. Web search
  2. Connectors – requests to your own systems with the credentials of the respective person. Connectors
  3. Mail – invitations and notifications to your mail server.

Complete, with diagram: Data flows.

Open points basebox answers for you

Some details depend on the specific environment or are fixed contractually; ask for them during contract negotiation:

  • Certifications and physical access controls of the Noris data center
  • Fixed egress addresses for firewall rules on your side
  • Backup scope, frequency and retention; recovery times
  • Availability of a private connection (VPN) and of IP allowlisting for inbound user access

Contact: datenschutz@basebox.ai.

Next step: Server