SOC 2 Type II, HIPAA, ISO 27001, and GDPR support, with the documentation your reviewers need.
Frameworks
- SOC 2 Type IICertified
- HIPAASupported via self-hosting
- ISO 27001Aligned
- GDPRSupported
- CCPACompliant
Privacy
- A standard DPA with SCCs for international transfers
- A current sub-processor list, with notice of material changes
- Regional hosting, or self-hosting inside your own boundary
- No AI model training on customer data
Request the documentation your security, legal, and procurement teams need to approve Basedash.
SOC 2 Type II report
Shared under NDA with qualified enterprise prospects and customers.
Security questionnaires
We complete SIG, CAIQ, and custom security questionnaires.
Data processing addendum
Signed DPA with SCCs for your legal and privacy review.
Penetration test summary
Summary of third-party penetration testing results on request.
Compliance FAQ
Is Basedash SOC 2 Type II certified?
Yes. Basedash is SOC 2 Type II certified, audited annually against the security, availability, and confidentiality trust services criteria, with continuous monitoring between audits. The current SOC 2 report is available to qualified prospects and customers under NDA.
Can Basedash support HIPAA workflows?
Basedash supports HIPAA workflows for protected health information (PHI) when deployed with the right customer controls. Healthcare teams commonly run Basedash in a private VPC or self-hosted deployment for additional control.
Does Basedash comply with GDPR and CCPA?
Basedash supports GDPR and CCPA obligations, including data subject access and deletion rights. A data processing addendum (DPA) with standard contractual clauses (SCCs) is available for international data transfers, and regional deployment or self-hosting options support data localization requirements.
Is Basedash ISO 27001 certified?
Basedash aligns its controls with ISO 27001 so it maps cleanly onto enterprise information security management programs. Reach out for current details on certification status and how Basedash fits your ISO 27001 requirements.
How do we get a copy of the SOC 2 report?
Enterprise prospects and customers can request the latest SOC 2 Type II report, penetration test summary, and other security documentation under NDA. Contact sales or your account team and we will share the current package for your security review.
Do you support enterprise procurement and security reviews?
Yes. Basedash supports enterprise procurement workflows, including completing security questionnaires (SIG, CAIQ, and custom), signing a DPA and master service agreement, and participating in legal and stakeholder review cycles. We help move evaluations through security, legal, and procurement efficiently.
Where is customer data stored, and who processes it?
Customer data is hosted in supported cloud regions, or fully inside your own infrastructure with a self-hosted or VPC deployment. A current sub-processor list is available with advance notice of material changes, and a data processing addendum governs how data is handled.