Skip to content
Security

Enterprise-grade security.

Built in from day one.

The controls your security team expects — SSO, SCIM, RBAC, encryption, audit logs, and self-hosting.

Security posture
All controls enforced

Single sign-on

SAML · OIDC · enforced

User provisioning

SCIM · 142 users synced

Access control

RBAC · row-level security

Encryption

TLS 1.2+ · AES-256 at rest

Audit logs

Streaming · 90d retention

Compliance

SOC 2 Type II · HIPAA

Controls

Defense in depth, end to end.

Identity, data, governance, and AI safety — covered by one platform.

Identity and access

Connect your identity provider and control exactly who sees what.

  • SSO with SAML 2.0 and OIDC (Okta, Entra ID, Google Workspace)
  • SCIM provisioning and deprovisioning
  • Role-based access control (RBAC)
  • Row-level and object-level permissions

Data protection

Your data is encrypted, isolated, and never used to train models.

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Per-customer logical data isolation
  • Customer data is never used to train AI models
  • Granular data retention and deletion controls

Monitoring and governance

Every query and change is traceable for your security team.

  • Native audit logs of access and changes
  • Query logs with full traceability
  • Governed metrics through the semantic layer
  • Configurable log retention and export

AI safety

AI runs inside your governance boundary, grounded in your data.

  • Answers are grounded in your governed sources, not freeform
  • Bring your own AI keys (OpenAI, Anthropic, Azure, Bedrock)
  • Generated SQL is reviewable and re-runnable
  • AI respects the same RBAC and row-level rules as users
Access

Access controls at a glance.

Everything your identity and security teams need to onboard with confidence.

CapabilityDetails
Single sign-on (SSO)SAML 2.0 and OIDC with any major identity provider
SCIM provisioningAutomatic user and group sync, instant deprovisioning
Role-based access controlWorkspace, group, and resource-level roles
Row-level securityRestrict rows per user, team, or attribute
Audit logsAccess, query, and configuration events with export
EncryptionTLS 1.2+ in transit, AES-256 at rest
Deployment

Run Basedash where you need it.

Managed cloud, private VPC, or fully self-hosted inside your perimeter.

Compliance

SOC 2 Type II, HIPAA, ISO 27001, and GDPR.

Basedash is SOC 2 Type II compliant and supports HIPAA workflows, ISO 27001 alignment, and GDPR obligations. Request reports and documentation for your security review.

Security FAQ

Is Basedash SOC 2 compliant?

Yes. Basedash is SOC 2 Type II compliant, audited annually with continuous monitoring. Enterprise customers can request the latest SOC 2 report and complete security documentation under NDA. Basedash also supports HIPAA workflows and aligns with ISO 27001 and GDPR requirements.

Does Basedash support SSO and SCIM?

Yes. Basedash supports single sign-on (SSO) using SAML 2.0 and OIDC with identity providers including Okta, Microsoft Entra ID, and Google Workspace. SCIM is supported for automatic user and group provisioning and instant deprovisioning, so access stays in sync with your identity provider.

How does Basedash control who can see which data?

Basedash enforces role-based access control (RBAC) alongside row-level and object-level permissions. Administrators control which sources, dashboards, and metrics each role can access, and row-level security restricts which records a user can see based on their team or attributes. AI chat and dashboards respect the same permission rules as every other user.

Does Basedash train AI models on our data?

No. Customer data is never used to train AI models. Basedash grounds AI answers in your governed data sources and semantic layer rather than generating freeform responses, and enterprise teams can bring their own AI provider keys to keep model usage within their existing vendor and governance programs.

How is our data encrypted and isolated?

All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Each customer's data is logically isolated, and enterprise teams can deploy in a private VPC or fully self-hosted environment so data never leaves their network boundary.

Are audit logs available for security reviews?

Yes. Basedash provides native audit logs covering access, queries, and configuration changes, with configurable retention and export. Every AI-generated query can be traced back to the underlying data and re-run for verification, giving security and compliance teams full visibility.

Can we run Basedash inside our own infrastructure?

Yes. Basedash offers managed cloud, private VPC, and fully self-hosted deployments using Docker, Kubernetes, or Helm. Self-hosted and VPC deployments keep all data inside your perimeter and support air-gapped environments, bring-your-own AI keys, and your own networking and retention policies.

Get started in under 30 minutes

We can help you migrate your data and dashboards from any other tool.