Licensed to be used in conjunction with basebox, only.
// security
Customer data center
Applies to
Product: Server · Location: customer data center · Audience: Security / Compliance reviewer
Security posture when the server stands in the customer's data center: the customer controls physical access, network and – without an operations contract – the entire operation. In this constellation basebox has no access unless you commission installation or operation and open a maintenance path for it.
What the customer controls
| Area | Control | Reference |
|---|---|---|
| Physical access | Your data center, your access rules | – |
| Network | Your network, your firewall, your segmentation; egress per your allowlist | Networking |
| Operating system, drivers, Kubernetes | Your Platform Operator (or basebox under an operations contract) | Server preparation |
| Storage and encryption at rest | Your disks, your storage class | Encryption |
| Backups | Your target, your retention | Backup & restore |
| Logs and monitoring | Your log stack, your SIEM | Logging · SIEM integration |
| Updates | You apply; basebox delivers and announces | Updates |
| Application and data | Your administrators, your users | Shared responsibility |
What basebox can – and cannot – do in this constellation
Without an operations contract: basebox delivers software (images, charts, models) via the registry, release notes, documentation and support. basebox has no access to the server, no telemetry, no insight into data or logs. Support is based on what you send basebox – logs, manifest, failure patterns (Troubleshooting).
With an operations contract: basebox accesses via the agreed path – PAM/VPN, time-limited, approved by you, logged, revocable (Remote maintenance). Physical access stays with you; basebox works remotely on the software stack.
Under data protection law
Without access basebox is not a processor – you are the controller, and there is no processing by basebox. With an operations contract the role must be regulated contractually because a maintenance access technically enables access to personal data (GDPR).
Outbound connections
A server in the customer network needs little outbound in normal operation. What you allow depending on usage:
| Purpose | Target | When |
|---|---|---|
| Container images and Helm charts | gitea.basebox.health (registry) |
Installation and updates – or via an internal mirror |
| Model weights | Hugging Face or model source | Initial installation, model change – or pre-loaded |
| Web search | Provider hosts (Staan: api.staan.ai) |
Only when enabled |
| Connectors | Your target systems | Mostly internal |
| Your mail server | Invitations, notifications | |
| Directory / SSO | Your LDAP / OIDC provider | Sign-in |
Without these rules the server runs air-gapped – web search and online downloads are unavailable (Air-gapped environments). Inbound, a server needs only HTTPS from your users and – under an operations contract – the maintenance path.
For the review
- The server is an asset in your data center like any other: access, rack, power, fire protection per your concept.
- Keep the egress rules as a list; every rule with its purpose.
- Decide whether and how basebox gets access – and document "no access" if that is your decision.
- Handover and boundaries of responsibility: Customer-managed operation.
Next step: Hosting at basebox