Skip to content

// security

Customer data center

Applies to

Product: Server · Location: customer data center · Audience: Security / Compliance reviewer

Security posture when the server stands in the customer's data center: the customer controls physical access, network and – without an operations contract – the entire operation. In this constellation basebox has no access unless you commission installation or operation and open a maintenance path for it.

What the customer controls

Area Control Reference
Physical access Your data center, your access rules –
Network Your network, your firewall, your segmentation; egress per your allowlist Networking
Operating system, drivers, Kubernetes Your Platform Operator (or basebox under an operations contract) Server preparation
Storage and encryption at rest Your disks, your storage class Encryption
Backups Your target, your retention Backup & restore
Logs and monitoring Your log stack, your SIEM Logging · SIEM integration
Updates You apply; basebox delivers and announces Updates
Application and data Your administrators, your users Shared responsibility

What basebox can – and cannot – do in this constellation

Without an operations contract: basebox delivers software (images, charts, models) via the registry, release notes, documentation and support. basebox has no access to the server, no telemetry, no insight into data or logs. Support is based on what you send basebox – logs, manifest, failure patterns (Troubleshooting).

With an operations contract: basebox accesses via the agreed path – PAM/VPN, time-limited, approved by you, logged, revocable (Remote maintenance). Physical access stays with you; basebox works remotely on the software stack.

Under data protection law

Without access basebox is not a processor – you are the controller, and there is no processing by basebox. With an operations contract the role must be regulated contractually because a maintenance access technically enables access to personal data (GDPR).

Outbound connections

A server in the customer network needs little outbound in normal operation. What you allow depending on usage:

Purpose Target When
Container images and Helm charts gitea.basebox.health (registry) Installation and updates – or via an internal mirror
Model weights Hugging Face or model source Initial installation, model change – or pre-loaded
Web search Provider hosts (Staan: api.staan.ai) Only when enabled
Connectors Your target systems Mostly internal
Mail Your mail server Invitations, notifications
Directory / SSO Your LDAP / OIDC provider Sign-in

Without these rules the server runs air-gapped – web search and online downloads are unavailable (Air-gapped environments). Inbound, a server needs only HTTPS from your users and – under an operations contract – the maintenance path.

For the review

  • The server is an asset in your data center like any other: access, rack, power, fire protection per your concept.
  • Keep the egress rules as a list; every rule with its purpose.
  • Decide whether and how basebox gets access – and document "no access" if that is your decision.
  • Handover and boundaries of responsibility: Customer-managed operation.

Next step: Hosting at basebox