Skip to content
Compliance

Compliance your team can trust.

SOC 2 Type II, HIPAA, ISO 27001, and GDPR — with the documentation your reviewers need.

Certifications

Mapped to the standards you run.

The frameworks enterprise security and compliance teams already require.

SOC 2 Type II

Certified

Audited annually against the security, availability, and confidentiality criteria with continuous monitoring.

HIPAA

Supported

Supports protected health information (PHI) workflows with strict access boundaries and a BAA for eligible plans.

ISO 27001

Aligned

Controls mapped to ISO 27001 so the platform fits cleanly into enterprise information security programs.

GDPR

Compliant

Supports data subject rights, regional data residency options, and a data processing addendum (DPA).

CCPA

Compliant

Honors California consumer privacy rights, including access and deletion requests.

DPA available

On request

Standard data processing addendum with standard contractual clauses (SCCs) for international transfers.

At a glance

Compliance status, in one table.

A quick reference for security questionnaires and vendor reviews.

Framework Status
SOC 2 Type II Certified
HIPAA Supported
ISO 27001 Aligned
GDPR Compliant
CCPA Compliant
Data handling

Clear answers on how data is handled.

Processing terms, sub-processors, residency, and AI data use — documented.

Data processing addendum

A standard DPA with standard contractual clauses governs how Basedash processes customer data on your behalf.

Sub-processors

A current list of sub-processors is available, with advance notice of material changes.

Data residency

Choose supported regional hosting, or self-host to keep all data inside your own boundary.

No model training

Customer data is never used to train AI models, and enterprise teams can bring their own AI keys.

Everything for your security review.

Request the documentation your security, legal, and procurement teams need to approve Basedash.

SOC 2 Type II report

Shared under NDA with qualified enterprise prospects and customers.

Security questionnaires

We complete SIG, CAIQ, and custom security questionnaires.

Data processing addendum

Signed DPA with SCCs for your legal and privacy review.

Penetration test summary

Summary of third-party penetration testing results on request.

Compliance FAQ

Is Basedash SOC 2 Type II certified?

Yes. Basedash is SOC 2 Type II certified, audited annually against the security, availability, and confidentiality trust services criteria, with continuous monitoring between audits. The current SOC 2 report is available to qualified prospects and customers under NDA.

Is Basedash HIPAA compliant?

Basedash supports HIPAA workflows for protected health information (PHI) with strict access boundaries, and a business associate agreement (BAA) is available on eligible plans. Healthcare teams commonly run Basedash in a private VPC or self-hosted deployment for additional control.

Does Basedash comply with GDPR and CCPA?

Yes. Basedash supports GDPR and CCPA obligations, including data subject access and deletion rights. A data processing addendum (DPA) with standard contractual clauses (SCCs) is available for international data transfers, and regional data residency or self-hosting options support data localization requirements.

Is Basedash ISO 27001 certified?

Basedash aligns its controls with ISO 27001 so it maps cleanly onto enterprise information security management programs. Reach out for current details on certification status and how Basedash fits your ISO 27001 requirements.

How do we get a copy of the SOC 2 report?

Enterprise prospects and customers can request the latest SOC 2 Type II report, penetration test summary, and other security documentation under NDA. Contact sales or your account team and we will share the current package for your security review.

Do you support enterprise procurement and security reviews?

Yes. Basedash supports enterprise procurement workflows, including completing security questionnaires (SIG, CAIQ, and custom), signing a DPA and master service agreement, and participating in legal and stakeholder review cycles. We help move evaluations through security, legal, and procurement efficiently.

Where is customer data stored, and who processes it?

Customer data is hosted in supported cloud regions, or fully inside your own infrastructure with a self-hosted or VPC deployment. A current sub-processor list is available with advance notice of material changes, and a data processing addendum governs how data is handled.

Get started in under 30 minutes

We can help you migrate your data and dashboards from any other tool.