Base44 Platform Security: Build and Scale Secure AI Apps
Security you can build on
Every app built on Base44 comes with AES-256 encryption, built-in security scans and AI-powered fixes – backed by SOC 2 Type II and ISO 27001 certification.
Compliance, covered
SOC 2 Type II
Independent audit of the design and operating effectiveness of our security controls.
ISO 27001
Certified information security management – the international standard.
GDPR
EU data protection standards, with a Data Processing Agreement available on request.
Your data, your rules
Control where your data lives, who can access it and whether it trains AI models.
Data residency
Choose the region where your app data is stored.
Training data opt-out
Opt your workspace's data out of AI model training.
Deleting your app's user data
Base44 supports a GDPR Deletion Flow to help you comply with users' right to erasure.
Your security, our priority.
We apply these practices at every stage – and independent auditors verify them.
Secure development life-cycle
Security runs through every stage of building Base44 – threat modeling, secure design, code reviews and penetration testing, so risks surface early and get fixed early.
Penetration testing
Internal teams and third-party firms test our defenses against real-world attack scenarios, based on OWASP methodologies. Our security team reviews, prioritizes and tracks every finding to resolution.
Encryption & key management
Base44 encrypts your app data in transit with TLS 1.2+ and at rest with AES-256, and manages secrets in a cloud key management service (KMS). Encryption covers backups too.
Secure payments & anti-fraud
Payments run through PCI DSS-certified providers. Base44 encrypts sensitive payment data in transit and never stores it, and a layered anti-fraud system combines specialized fraud-detection providers with Base44's own detection.
Third-party risk management
We assess every vendor against defined security and compliance requirements, and re-validate periodically.
Bug bounty program
Independent security researchers probe our systems and disclose what they find – responsibly. Our security team reviews and validates every submission, prioritizes confirmed vulnerabilities by severity and fixes them.
Disaster Recovery & Business Continuity
We maintain defined Recovery Time and Recovery Point Objectives aligned with industry standards, backed by frequent automated backups and documented recovery procedures. Detailed commitments are available to Enterprise customers as part of their Service Level Agreement.
24/7 Security Monitoring
Our platform is monitored around the clock by a 24/7/365 Security Operations Center (SOC), powered by SIEM technology and supported by a dedicated security team.
Incident Response
A dedicated Security Incident Response Team operates under a formal Incident Response Plan and Security Incident Management Policy, ensuring security events are identified, contained, and resolved quickly.
Subprocessor directory
Third-party partners who help us securely process your data.
Mongo(US)
Data storage and hosting
SendGrid(US)
Email transmission and external communication
Render(US)
Server services
GCP - Google cloud(US)
Analytics services
OpenAI(US)
API calls to LLM
Anthropic(US)
API calls to LLM
Wix.com Ltd.(IL)
Providing and improving the services
Datadog(US)
General logging purposes
Langfuse(DE)
LLM logging
Security for every app
Built-in security scans
Run a security scan from every app's Security tab. It checks for vulnerable third-party dependencies (SCA), insecure code patterns (SAST), exposed secrets, missing login checks and weak data access rules. Each finding comes with a severity rating and a plain explanation – and AI fixes it for you.
Data access control
App access
Secrets management
Data version history
Connector security
Scan with Wiz
Extensible security
Workspace Security
Give every team a safe space to build.
Workspace roles
Owner, Editor and Viewer roles on every workspace – enterprise workspaces add Admin. Each role scopes what a builder can do, from full control to read-only.
Workspace authentication
Sign in to Base44 with Google, Apple or email and password – backed by anti-bot controls, email verification and optional 2-FA with an authenticator app, or SMS on paid plans. Organizations can sign-in with their SSO (OIDC) – Entra ID, Okta, Google, and more.
SSO enforcement
Enterprises can enforce organizational SSO across every app built in the workspace.
Verified workspace domain
Verify your organization's domain with a DNS TXT record. Base44 uses it to enforce access policies and auto-onboard your team through SSO.
IP allowlist
Restrict workspace and app access to specific networks – single IPs, CIDR ranges, IPv6 included. Requests from anywhere else get a 403.
Workspace security center
One place for workspace admins to scan and review security issues across every app in the workspace.
Workspace Governance & Monitoring
From who publishes to what each builder spends – every lever in admin hands, and the logs to prove it.
- Enterprise
SCIM provisioning
Run the full lifecycle from your IdP: create, update, deactivate and delete accounts and groups, with stable external-ID matching.
- Enterprise
Role-based publishing control
Control who can publish and which visibility levels each role can use, with defaults applied across the workspace. Anyone blocked from publishing directly can send an approval request, so changes reach end users only through an approved path.
- Enterprise
Connector management
Workspace admins control which connectors are available across every app, agent and Superagent. Enable or disable connectors workspace-wide – including shared and app-user connectors – and review which apps are affected before confirming a change.
- Enterprise
Credit limits
Set a monthly credit limit per member. Spend stays predictable – and no single builder can burn through the budget.
- Enterprise
Monitoring API
Pull workspace usage, health and analytics into your own tools through the Monitoring API – with workspace API keys that carry only the permissions you give them.
- Enterprise
Audit logs
A complete record of who did what across your workspace – sign-ins, publishing and governance events included. Stream events into your own monitoring tools through the Audit Logs API.
The questions security reviews ask.
Is Base44 secure?
Base44 is SOC 2 Type II and ISO 27001 certified, GDPR compliant and independently penetration-tested. Every app comes with built-in security scans, row-level security and encrypted secrets – and enterprise workspaces add SSO enforcement, IP allowlists, full audit logs and more.
What compliance certifications does Base44 have?
Base44 has SOC 2 Type II, confirmed by independent audit, and ISO 27001 certification. Base44 is also GDPR compliant, with a Data Processing Agreement available. Request reports from the compliance section above.
Where is my Base44 data stored?
Base44 stores your app data in the US by default. Workspaces on Elite and Enterprise plans can choose other regions to store instead.
Is my data encrypted?
Base44 encrypts your data in transit with TLS 1.2+ and at rest with AES-256.
Can I use my company's SSO with Base44?
Yes, at two levels. Apps on Elite plans and up can offer sign-in through any OIDC identity provider – Google Workspace, Microsoft, GitHub, Okta and more. On enterprise workspaces, builders sign in with the organization's own SSO, and Enterprise admins can enforce it across every app in the workspace.
Does Base44 support two-factor authentication?
Yes. Turn on two-factor authentication with an authenticator app, or SMS on paid plans – Base44 then asks for your password and a verification code each time you sign in.
Can the AI change parts of my app I want protected?
You set the rules the AI follows in each app: add custom instructions, and freeze files or entities so the AI never modifies protected areas.