basient

Trust Center

Security is the product.

Basient was designed for regulated workloads from the first commit — not retrofitted for the questionnaire. Here is exactly what we do, what we hold, and what you can verify.

Certifications & frameworks

SOC 2 Type II

Certified

Independently audited controls for security, availability and confidentiality. Full report available under NDA.

GDPR

Compliant

We act as processor with a signed DPA, Standard Contractual Clauses for transfers, and EU data residency available.

LGPD

Compliant

Full alignment with Lei 13.709/2018: named DPO (encarregado), Brazilian data residency, and data-subject rights tooling.

ISO 27001

In progress

Certification under way. Our ISMS is already operating; certificate expected in 2026.

HIPAA

BAA available

Business Associate Agreements for healthcare workloads on dedicated deployments.

Penetration testing

Annual

Third-party penetration test every 12 months; executive summary available on request.

Data protection

Encryption everywhere. Retention nowhere.

In transit: TLS 1.3 only; internal service-to-service traffic is mTLS. At rest: AES-256-GCM on every datastore, HSM-managed keys. Secrets: provider API keys live in a hardened vault, resolved at load, cached only in memory — never in env vars, code, logs or serialized config.

Zero-retention mode: prompts and completions are never written to disk — only usage metadata (tokens, model, cost, latency) is recorded. PII redaction: optional inline redaction before requests leave your tenant boundary. No training: your data is never used to train models — ours or anyone else's. Contractually guaranteed in the DPA.

Data residency

Data stays where the contract says.

RegionLocationFramework
EUFrankfurt (eu-central-1)GDPR
USVirginia (us-east-1)SOC 2
BRSão Paulo (sa-east-1)LGPD

Model-provider routing respects residency: if a tenant is pinned to EU, only EU-hosted model endpoints are eligible routes. No silent cross-border hop.

Access & identity

Least privilege, enforced.

  • — SAML 2.0 / OIDC SSO; SCIM 2.0 provisioning and deprovisioning
  • — Fine-grained RBAC; least-privilege by default; audit log on every privileged action
  • — Production access: just-in-time, MFA-enforced, reviewed quarterly

Reliability

Failure is loud, by design.

  • — 99.99% uptime SLA (Enterprise); public status page: status.basient.com
  • — Multi-AZ; RPO ≤ 5 min, RTO ≤ 1 h; DR exercises twice a year
  • — Mid-stream failures are terminal and visible — partial outcomes are recorded as partial, never silently retried or double-billed

Subprocessors & agreements

Paper that matches practice.

  • Subprocessor list — including model providers, each bound by zero-retention terms where offered
  • Data Processing Agreement — GDPR and LGPD in one signable document
  • — Change notification: 30 days before any new subprocessor

Responsible disclosure

Found something? We want to know.

  • security@basient.com · PGP key published
  • /.well-known/security.txt
  • — Safe harbor for good-faith research; response SLA: 48 h triage

Your security team has questions. Good.

Request the security packet — SOC 2 report, pen test summary, DPA and architecture overview, under NDA, within one business day.