Basis
Security

Built for regulated work.

Your cost data and pricing strategies are crown jewels. Basis protects them with enterprise-grade encryption, access controls, and compliance certifications.

Compliance

Certifications and frameworks

Meeting the standards your customers and auditors require.

SOC 2 Type IIIn progress
GDPR
CCPA
HIPAA (BAA)
CMMC-L2
ITAR-friendly
Security controls

Defense in depth

Multiple layers of protection for your most sensitive data.

AES-256 at rest

All data encrypted with AES-256-GCM at rest. Database fields, file uploads, and backups are encrypted before they touch disk.

TLS 1.3 in transit

Every connection uses TLS 1.3 with strong cipher suites. HSTS enforced. Certificate transparency monitored.

SSO / SCIM

Enterprise SSO via SAML 2.0 and OIDC. SCIM for automated user provisioning and deprovisioning. MFA enforced.

Full audit log

Every create, read, update, and delete is logged with actor, timestamp, and IP. Exportable and query-able. 7-year retention.

Least-privilege roles

Four built-in roles with granular permissions. Custom roles available on Enterprise. Tenant isolation enforced at the database layer.

Pen-tested annually

Annual third-party penetration tests by an independent firm. Findings tracked to resolution. Reports available under NDA.

Roadmap

Certification timeline

Our path to the highest levels of compliance assurance.

2025 Q4

SOC 2 Type I

Controls design validated

2026 Q1

SOC 2 Type II audit begins

Observation window opens

2026 Q3

SOC 2 Type II certified

Full operational effectiveness

2027 H1

FedRAMP Moderate

On the roadmap

Trust center

Request our security package

Everything you need for your vendor security review.

Security whitepaper

Architecture overview, data flow diagrams, and control descriptions in a single document.

Download PDF

Pen-test report

Latest third-party penetration test results available under NDA for qualified prospects.

Request under NDA

Security review call

Schedule a 30-minute call with our security team to discuss your specific requirements.

Schedule a call

Security questions?

Our team is happy to walk through our security posture, share documentation, or discuss your compliance requirements.