Licensed to be used in conjunction with basebox, only.
// security
Hosting at basebox
Applies to
Product: Server · Location: basebox data center · Audience: Security / Compliance reviewer
A customer-owned dedicated server that physically stands in the basebox data center: what basebox controls (physical, surrounding network), what stays with the customer (application, data, operation – unless commissioned) – and why this is still Server, not Cloud.
Why this is not Cloud
| Server hosted at basebox | basebox Cloud | |
|---|---|---|
| Hardware | Dedicated to one customer – FAST LTA or customer-owned | basebox's own server, shared by several customers in isolated environments |
| Software stack | Runs only for this customer on this machine | Platform operated by basebox |
| Operation of the software stack | Customer – or basebox when commissioned separately | Always basebox |
| Physical location | Space provided by basebox | Noris, Munich |
| Language model | Local on the server | Local on the Cloud server |
| basebox access to the software stack | Only under an operations contract, via PAM/VPN | Always, as platform operator |
| Documented under | Server | Cloud |
Hosting changes exactly one row in the Responsibilities table: the data center. Everything else in the Server columns still applies.
What basebox controls
- Physical access to the rack: entry, rack lock, power, cooling, fire protection – the housing service.
- The surrounding network: uplink, perimeter firewall, the connection of your users (internet with HTTPS or VPN) and – if you wish – the egress rules at the perimeter. Which rules apply you agree with basebox; the default stance is "only what you allow".
- Under an operations contract additionally the software stack – then as under Remote maintenance, with the difference that basebox would also have the maintenance path physically on site. Even then: time-limited, approved, logged.
What stays with the customer
- Ownership of hardware and disks. At the end you take the machine back or have the disks destroyed according to your concept – agree the procedure in advance (Deletion).
- Application administration and data – as in every Server model.
- Operation of the software stack if not commissioned: your Platform Operator works remotely (VPN/bastion) on the machine; basebox provides the access path.
- Encryption at rest – particularly important when a third party has physical access to the machine: encrypted disks protect data against removal of a disk (Encryption).
Under data protection law
Housing alone – power, network, rack – is usually not processing on behalf, because basebox has no access to data without an operations contract. Physical access to the machine is, however, a possibility of access; hosting therefore comes with a contractual arrangement (access rules, confidentiality, a DPA where applicable) and technically with storage encryption.
What users notice
Nothing except the access path: users reach the hosted server over the internet via HTTPS or via a VPN between your network and the basebox data center (VPN & networking). Connectors to your internal systems need the reverse path – from the hosted server into your network, usually via the same VPN.
For the review
- Describe the deployment as basebox Server, location basebox data center, operated by customer/basebox – never as Cloud.
- Request location, certifications and access rules of the data center (datenschutz@basebox.ai).
- Encrypted disks are the single most important control here.
- Agree return/destruction of the disks before commissioning.
Next step: Remote maintenance