Licensed to be used in conjunction with basebox, only.
// security
Shared responsibility
Applies to
Product: Demo · Cloud · Server · Audience: Security / Compliance reviewer
Who is responsible for what, per deployment model. This page mirrors the central table Responsibilities from the compliance perspective: not "who installs Kubernetes" but "who carries which security and data protection duty". For contractual boundaries the respective contract governs; the tables here are the template for it.
The principle
Two things sit with the customer in every model: the application administration (users, roles, models, apps, knowledge bases, connectors, policies, audit) and the responsibility for the data under data protection law. That basebox operates the infrastructure – always in the Cloud, on a server only when commissioned – does not make basebox the administrator of your organization nor the controller of your data.
The matrix
| Duty | Self-managed server | Server operated by basebox | basebox Cloud | Demo |
|---|---|---|---|---|
| Physical security, data center | Customer | Customer – or basebox when hosted at basebox | basebox | basebox (test environment) |
| Harden and patch OS, drivers, Kubernetes | Customer | basebox, if in scope | basebox | basebox |
| Keep basebox software current | Customer applies; basebox delivers and announces | basebox | basebox | basebox |
| Network, firewall, egress | Customer | Customer network with the customer; access path with basebox | Platform network basebox; connection and rules customer | – |
| Encryption at rest (storage layer) | Customer | basebox if in scope; otherwise customer | basebox | – |
| Backup and restore | Customer | basebox, if agreed | basebox | none |
| Monitoring, alerting | Customer | basebox, if agreed | basebox | – |
| Identities, roles, groups | Customer | Customer | Customer | – |
| Policies: audit detail level, retention, web search, connectors, write permissions | Customer | Customer | Customer | – |
| App approvals, knowledge bases, content | Customer | Customer | Customer | Users, test data |
| Model selection and approval per app | Customer | Customer | Customer (from what basebox provides) | – |
| Review and export the audit log | Customer | Customer | Customer | – |
| Detect and report security incidents in the infrastructure | Customer | basebox in scope, customer outside | basebox informs the customer without delay | – |
| Fix security vulnerabilities in the software | basebox | basebox | basebox | basebox |
| Risk classification of the AI use, human oversight, transparency towards end users, AI literacy | Customer (deployer) | Customer | Customer | – |
| Document model choice, licence and origin | basebox (Model register); customer for self-connected models | basebox / customer | basebox | – |
| Data protection role | Customer controller; basebox without access | Customer controller; basebox role contractual (maintenance access) | Customer controller; basebox processor (DPA) | no real data |
How to read the matrix
- "Customer" can be your own IT or a third party you commission.
- "basebox, if in scope" means: can be part of an operations contract but is not automatically included. A Server licence is a software licence; infrastructure operation is a separate commission.
- Hosting at basebox changes only the row Physical security, data center. Everything else in the Server columns still applies – a hosted server is not Cloud (Hosting at basebox).
- The Demo column is not a distribution of responsibility but the reminder that no real data belongs there.
What basebox commits to in every model
From the Compliance document and the Infrastructure policy:
- Release notes and changelog for every version; announcement of security-relevant updates by e-mail.
- Security tests before every release: static code analysis, dependency scan, CVE check, unit tests, test installation, manual QA; release under the four-eyes principle.
- Immediate information of affected customers in case of known systemic risks or security-relevant incidents.
- Documentation of source, licence and version of the provided models; no change to weights other than quantization.
- No provision of models that violate Art. 5 EU AI Act.
What the customer carries in every model
- The decision which data is processed in basebox – and the rule about it for users.
- The configuration of the policies: audit detail level and retention, web search, connectors, write permissions, app approvals (Policies).
- Human oversight: basebox offers no manual pre-review of AI outputs; checking the results is part of your process (Safety notice).
- The duties as deployer under the EU AI Act (Compliance).
Next step: Data flows