The controls your security team expects: SSO, SCIM, RBAC, encryption, audit logs, and self-hosting.
Single sign-on
SAML · OIDC · enforced
User provisioning
SCIM · 142 users synced
Access control
RBAC · row-level security
Encryption
TLS 1.2+ · AES-256 at rest
Audit logs
Streaming · 90-day retention
Compliance
SOC 2 Type II · HIPAA
Data protection
Each customer's data is logically isolated, with granular retention and deletion controls.
AI safety
Answers follow the same RBAC and row-level rules as your users. Bring your own keys from OpenAI, Anthropic, Azure, or Bedrock.
Everything your identity and security teams need to onboard with confidence.
| Capability | Details |
|---|---|
| Single sign-on (SSO) | SAML 2.0 and OIDC with any major identity provider |
| SCIM provisioning | User lifecycle, group, and membership sync from a compatible IdP |
| Role-based access control | Workspace, group, and resource-level roles |
| Row-level security | Restrict rows per user, team, or attribute |
| Audit logs | Access, query, and configuration events with export |
Managed cloud, private VPC, or fully self-hosted inside your perimeter.
Compliance
HIPAA and GDPR needs are supported through private VPC and self-hosted deployments. Request reports and documentation for your security review.
Security FAQ
Is Basedash SOC 2 compliant?
Yes. Basedash is SOC 2 Type II compliant, audited annually with continuous monitoring. Enterprise customers can request the latest SOC 2 report and complete security documentation under NDA. Basedash also supports HIPAA and GDPR needs through deployment options such as private VPC and self-hosting, and aligns controls with ISO 27001 requirements.
Does Basedash support SSO and SCIM?
Yes. Basedash supports single sign-on (SSO) using SAML 2.0 and OIDC with identity providers including Okta, Microsoft Entra ID, and Google Workspace. SCIM supports user and group provisioning from compatible identity providers, including user deactivation when the provider sends that lifecycle change.
How does Basedash control who can see which data?
Basedash enforces role-based access control (RBAC) alongside row-level and object-level permissions. Administrators control which sources, dashboards, and metrics each role can access, and row-level security restricts which records a user can see based on their team or attributes. AI chat and dashboards respect the same permission rules as every other user.
Does Basedash train AI models on our data?
No. Customer data is never used to train AI models. Basedash grounds AI answers in your governed data sources and semantic layer rather than generating freeform responses, and enterprise teams can bring their own AI provider keys to keep model usage within their existing vendor and governance programs.
How is our data encrypted and isolated?
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Each customer's data is logically isolated, and enterprise teams can deploy in a private VPC or fully self-hosted environment so data never leaves their network boundary.
Are audit logs available for security reviews?
Yes. Basedash provides native audit logs covering access, queries, and configuration changes, with configurable retention and export. Every AI-generated query can be traced back to the underlying data and re-run for verification, giving security and compliance teams full visibility.
Can we run Basedash inside our own infrastructure?
Yes. Basedash offers managed cloud, private VPC, and fully self-hosted deployments using Docker, Kubernetes, or Helm. Self-hosted and VPC deployments keep all data inside your perimeter and support air-gapped environments, bring-your-own AI keys, and your own networking and retention policies.