Trust Center
Security is the product.
Basient was designed for regulated workloads from the first commit — not retrofitted for the questionnaire. Here is exactly what we do, what we hold, and what you can verify.
Certifications & frameworks
SOC 2 Type II
CertifiedIndependently audited controls for security, availability and confidentiality. Full report available under NDA.
GDPR
CompliantWe act as processor with a signed DPA, Standard Contractual Clauses for transfers, and EU data residency available.
LGPD
CompliantFull alignment with Lei 13.709/2018: named DPO (encarregado), Brazilian data residency, and data-subject rights tooling.
ISO 27001
In progressCertification under way. Our ISMS is already operating; certificate expected in 2026.
HIPAA
BAA availableBusiness Associate Agreements for healthcare workloads on dedicated deployments.
Penetration testing
AnnualThird-party penetration test every 12 months; executive summary available on request.
Data protection
Encryption everywhere. Retention nowhere.
In transit: TLS 1.3 only; internal service-to-service traffic is mTLS. At rest: AES-256-GCM on every datastore, HSM-managed keys. Secrets: provider API keys live in a hardened vault, resolved at load, cached only in memory — never in env vars, code, logs or serialized config.
Zero-retention mode: prompts and completions are never written to disk — only usage metadata (tokens, model, cost, latency) is recorded. PII redaction: optional inline redaction before requests leave your tenant boundary. No training: your data is never used to train models — ours or anyone else's. Contractually guaranteed in the DPA.
Data residency
Data stays where the contract says.
| Region | Location | Framework |
|---|---|---|
| EU | Frankfurt (eu-central-1) | GDPR |
| US | Virginia (us-east-1) | SOC 2 |
| BR | São Paulo (sa-east-1) | LGPD |
Model-provider routing respects residency: if a tenant is pinned to EU, only EU-hosted model endpoints are eligible routes. No silent cross-border hop.
Access & identity
Least privilege, enforced.
- — SAML 2.0 / OIDC SSO; SCIM 2.0 provisioning and deprovisioning
- — Fine-grained RBAC; least-privilege by default; audit log on every privileged action
- — Production access: just-in-time, MFA-enforced, reviewed quarterly
Reliability
Failure is loud, by design.
- — 99.99% uptime SLA (Enterprise); public status page: status.basient.com
- — Multi-AZ; RPO ≤ 5 min, RTO ≤ 1 h; DR exercises twice a year
- — Mid-stream failures are terminal and visible — partial outcomes are recorded as partial, never silently retried or double-billed
Subprocessors & agreements
Paper that matches practice.
- — Subprocessor list — including model providers, each bound by zero-retention terms where offered
- — Data Processing Agreement — GDPR and LGPD in one signable document
- — Change notification: 30 days before any new subprocessor
Responsible disclosure
Found something? We want to know.
- — security@basient.com · PGP key published
- — /.well-known/security.txt
- — Safe harbor for good-faith research; response SLA: 48 h triage
Your security team has questions. Good.
Request the security packet — SOC 2 report, pen test summary, DPA and architecture overview, under NDA, within one business day.