SOC 2 Type II
CertifiedAudited annually against the security, availability, and confidentiality criteria with continuous monitoring.
SOC 2 Type II, HIPAA, ISO 27001, and GDPR support — with the documentation your reviewers need.
The frameworks enterprise security and compliance teams already require.
Audited annually against the security, availability, and confidentiality criteria with continuous monitoring.
Supports protected health information (PHI) workflows when deployed with the right customer controls, typically through private VPC or self-hosted environments.
Controls mapped to ISO 27001 so the platform fits cleanly into enterprise information security programs.
Supports GDPR obligations through data subject workflows, regional deployment options, self-hosting, and a data processing addendum (DPA).
Honors California consumer privacy rights, including access and deletion requests.
Standard data processing addendum with standard contractual clauses (SCCs) for international transfers.
A quick reference for security questionnaires and vendor reviews.
| Framework | Status | Coverage |
|---|---|---|
| SOC 2 Type II | Certified | Annual audit, report available under NDA |
| HIPAA | Supported via self-hosting | PHI workflows with customer-controlled deployment |
| ISO 27001 | Aligned | Controls mapped to ISO 27001 program |
| GDPR | Supported | DPA, SCCs, data subject rights, self-hosting options |
| CCPA | Compliant | Access and deletion rights honored |
Processing terms, sub-processors, residency, and AI data use — documented.
A standard DPA with standard contractual clauses governs how Basedash processes customer data on your behalf.
A current list of sub-processors is available, with advance notice of material changes.
Choose supported regional hosting, or self-host to keep all data inside your own boundary.
Customer data is never used to train AI models, and enterprise teams can bring their own AI keys.
Request the documentation your security, legal, and procurement teams need to approve Basedash.
SOC 2 Type II report
Shared under NDA with qualified enterprise prospects and customers.
Security questionnaires
We complete SIG, CAIQ, and custom security questionnaires.
Data processing addendum
Signed DPA with SCCs for your legal and privacy review.
Penetration test summary
Summary of third-party penetration testing results on request.
Yes. Basedash is SOC 2 Type II certified, audited annually against the security, availability, and confidentiality trust services criteria, with continuous monitoring between audits. The current SOC 2 report is available to qualified prospects and customers under NDA.
Basedash supports HIPAA workflows for protected health information (PHI) when deployed with the right customer controls. Healthcare teams commonly run Basedash in a private VPC or self-hosted deployment for additional control.
Basedash supports GDPR and CCPA obligations, including data subject access and deletion rights. A data processing addendum (DPA) with standard contractual clauses (SCCs) is available for international data transfers, and regional deployment or self-hosting options support data localization requirements.
Basedash aligns its controls with ISO 27001 so it maps cleanly onto enterprise information security management programs. Reach out for current details on certification status and how Basedash fits your ISO 27001 requirements.
Enterprise prospects and customers can request the latest SOC 2 Type II report, penetration test summary, and other security documentation under NDA. Contact sales or your account team and we will share the current package for your security review.
Yes. Basedash supports enterprise procurement workflows, including completing security questionnaires (SIG, CAIQ, and custom), signing a DPA and master service agreement, and participating in legal and stakeholder review cycles. We help move evaluations through security, legal, and procurement efficiently.
Customer data is hosted in supported cloud regions, or fully inside your own infrastructure with a self-hosted or VPC deployment. A current sub-processor list is available with advance notice of material changes, and a data processing addendum governs how data is handled.