Security
Your data stays yours.
Basis is a research tool for investment teams. The documents, extractions, and notes you bring to it belong to you. This page explains how we protect them.
Five controls that set the baseline.
Enterprise customers receive the full security questionnaire on request. These are the top-level commitments.
SOC 2 Type II (in progress)
Controls are designed to meet the Trust Services Criteria for security, availability, and confidentiality. Third-party attestation is in progress.
Encryption in transit and at rest
All traffic travels over TLS 1.2 or higher. Data at rest is encrypted with AES-256, with keys managed per environment.
SSO / SAML (Enterprise)
Enterprise workspaces connect through your identity provider via SAML 2.0. SCIM provisioning keeps seat access current as your roster changes.
Data isolation per workspace
Each workspace is logically isolated at the data layer. No customer can access another customer's documents, extractions, or notes.
Audit logging
Every read, write, export, and authentication event is recorded in a tamper-evident log. Team and Enterprise customers can export the full log.
We do not train on your content.
When you upload a filing, a transcript, or a PDF, that document is yours. Basis reads it to extract figures and draft analysis for you. It is not stored in a training corpus, and it does not improve a shared model.
The same applies to notes you write, tables you build, and the research library your team accumulates. None of that content is used to train models, whether ours or those of our subprocessors. All subprocessors are bound by data-processing agreements that reflect this restriction.
Documents are isolated per workspace. An extraction or note created in one workspace is never visible to another, regardless of plan or account status.
Encryption, access, retention, and residency.
Encryption
All data in transit is encrypted over TLS 1.2 or higher. Data at rest is encrypted with AES-256. Encryption keys are environment-scoped and rotated on a scheduled cycle. Backups are encrypted under the same scheme as primary storage.
Access controls
Internal access to production systems follows a least-privilege model. Engineers do not have standing access to customer data. Access to production is role-based, logged, and requires multi-factor authentication. Credential rotation is enforced automatically.
Within your workspace, seat-level permissions let admins control who can read, export, or manage documents. Team and Enterprise plans include role-based permissions and a full audit trail exportable in structured format.
Retention and deletion
Retention is customer-controlled. You can delete a document, an extraction, or your entire workspace at any time. Deletion removes the document and the derived extractions from active storage. Backup copies are purged on a 30-day rolling cycle following deletion. If you close your account, we send a confirmation and complete the purge within that window.
Data residency
By default, data is stored in US-based infrastructure. Enterprise customers with specific residency requirements should contact us before signing. We will confirm what is available and commit to it in the agreement.
Who processes your data on our behalf.
Basis uses a limited number of subprocessors to deliver the service. All subprocessors are bound by data-processing agreements that restrict their use of customer data to providing the specific service contracted.
- Cloud infrastructure. We run on a major US cloud provider. Infrastructure includes compute, object storage, and managed databases. No customer data leaves the contracted regions without an explicit residency agreement in place.
- LLM API. Document extraction and analysis drafting use a third-party large language model API. Customer content sent to the LLM API is not used to train that provider's models, per our data-processing agreement. Content is processed transiently and is not retained by the provider beyond the request window.
- Authentication. Login and session management use a third-party authentication provider. Only authentication metadata (email address and session token) is shared with this provider. Document contents are never sent to it.
Enterprise customers may request the current subprocessor list and the applicable data-processing agreements before signing. Send the request to security@basisresearch.tech.
Report a security issue.
If you believe you have found a security vulnerability in Basis, please report it to security@basisresearch.tech. We ask that you give us reasonable time to investigate and address the issue before public disclosure. We will acknowledge receipt within one business day and keep you informed as we work toward a fix. We do not pursue legal action against researchers who report issues in good faith and follow coordinated disclosure.
Where our compliance posture is headed.
SOC 2 Type II attestation is in progress. Penetration testing runs on a scheduled cycle. Additional compliance frameworks relevant to regulated investment managers, including custodian-review questionnaires and fund-specific requirements, are on our roadmap for the next twelve months. Enterprise customers with specific compliance timelines are encouraged to start the conversation early so we can plan together.
This page is updated as our posture matures. Material changes are noted in the changelog.
Security questions before you sign?
Enterprise and Team customers can request the full questionnaire, data-processing agreements, and subprocessor list.