Base44 Platform Security: Build and Scale Secure AI Apps

Security you can build on

Every app built on Base44 comes with AES-256 encryption, built-in security scans and AI-powered fixes – backed by SOC 2 Type II and ISO 27001 certification.

Compliance, covered

SOC 2 Type II

Independent audit of the design and operating effectiveness of our security controls.

ISO 27001

Certified information security management – the international standard.

View Certification

GDPR

EU data protection standards, with a Data Processing Agreement available on request.

Overview

Your data, your rules

Control where your data lives, who can access it and whether it trains AI models.

Data residency

Choose the region where your app data is stored.

Learn more

Training data opt-out

Opt your workspace's data out of AI model training.

Deleting your app's user data

Base44 supports a GDPR Deletion Flow to help you comply with users' right to erasure.

Your security, our priority.

We apply these practices at every stage – and independent auditors verify them.

Secure development life-cycle

Security runs through every stage of building Base44 – threat modeling, secure design, code reviews and penetration testing, so risks surface early and get fixed early.

Penetration testing

Internal teams and third-party firms test our defenses against real-world attack scenarios, based on OWASP methodologies. Our security team reviews, prioritizes and tracks every finding to resolution.

Encryption & key management

Base44 encrypts your app data in transit with TLS 1.2+ and at rest with AES-256, and manages secrets in a cloud key management service (KMS). Encryption covers backups too.

Secure payments & anti-fraud

Payments run through PCI DSS-certified providers. Base44 encrypts sensitive payment data in transit and never stores it, and a layered anti-fraud system combines specialized fraud-detection providers with Base44's own detection.

Third-party risk management

We assess every vendor against defined security and compliance requirements, and re-validate periodically.

Bug bounty program

Independent security researchers probe our systems and disclose what they find – responsibly. Our security team reviews and validates every submission, prioritizes confirmed vulnerabilities by severity and fixes them.

Disaster Recovery & Business Continuity

We maintain defined Recovery Time and Recovery Point Objectives aligned with industry standards, backed by frequent automated backups and documented recovery procedures. Detailed commitments are available to Enterprise customers as part of their Service Level Agreement.

24/7 Security Monitoring

Our platform is monitored around the clock by a 24/7/365 Security Operations Center (SOC), powered by SIEM technology and supported by a dedicated security team.

Incident Response

A dedicated Security Incident Response Team operates under a formal Incident Response Plan and Security Incident Management Policy, ensuring security events are identified, contained, and resolved quickly.

Subprocessor directory

Third-party partners who help us securely process your data.

Security for every app

Built-in security scans

Run a security scan from every app's Security tab. It checks for vulnerable third-party dependencies (SCA), insecure code patterns (SAST), exposed secrets, missing login checks and weak data access rules. Each finding comes with a severity rating and a plain explanation – and AI fixes it for you.

Data access control

App access

Secrets management

Data version history

Connector security

Scan with Wiz

Extensible security

Workspace Security

Give every team a safe space to build.

Owner, Editor and Viewer roles on every workspace – enterprise workspaces add Admin. Each role scopes what a builder can do, from full control to read-only.

Sign in to Base44 with Google, Apple or email and password – backed by anti-bot controls, email verification and optional 2-FA with an authenticator app, or SMS on paid plans. Organizations can sign-in with their SSO (OIDC) – Entra ID, Okta, Google, and more.

Enterprises can enforce organizational SSO across every app built in the workspace.

Verify your organization's domain with a DNS TXT record. Base44 uses it to enforce access policies and auto-onboard your team through SSO.

Restrict workspace and app access to specific networks – single IPs, CIDR ranges, IPv6 included. Requests from anywhere else get a 403.

One place for workspace admins to scan and review security issues across every app in the workspace.

Workspace Governance & Monitoring

From who publishes to what each builder spends – every lever in admin hands, and the logs to prove it.

  1. Enterprise

SCIM provisioning

Run the full lifecycle from your IdP: create, update, deactivate and delete accounts and groups, with stable external-ID matching.

  1. Enterprise

Role-based publishing control

Control who can publish and which visibility levels each role can use, with defaults applied across the workspace. Anyone blocked from publishing directly can send an approval request, so changes reach end users only through an approved path.

  1. Enterprise

Connector management

Workspace admins control which connectors are available across every app, agent and Superagent. Enable or disable connectors workspace-wide – including shared and app-user connectors – and review which apps are affected before confirming a change.

  1. Enterprise

Credit limits

Set a monthly credit limit per member. Spend stays predictable – and no single builder can burn through the budget.

  1. Enterprise

Monitoring API

Pull workspace usage, health and analytics into your own tools through the Monitoring API – with workspace API keys that carry only the permissions you give them.

  1. Enterprise

Audit logs

A complete record of who did what across your workspace – sign-ins, publishing and governance events included. Stream events into your own monitoring tools through the Audit Logs API.

The questions security reviews ask.

Is Base44 secure?

Base44 is SOC 2 Type II and ISO 27001 certified, GDPR compliant and independently penetration-tested. Every app comes with built-in security scans, row-level security and encrypted secrets – and enterprise workspaces add SSO enforcement, IP allowlists, full audit logs and more.

What compliance certifications does Base44 have?

Base44 has SOC 2 Type II, confirmed by independent audit, and ISO 27001 certification. Base44 is also GDPR compliant, with a Data Processing Agreement available. Request reports from the compliance section above.

Where is my Base44 data stored?

Base44 stores your app data in the US by default. Workspaces on Elite and Enterprise plans can choose other regions to store instead.

Is my data encrypted?

Base44 encrypts your data in transit with TLS 1.2+ and at rest with AES-256.

Can I use my company's SSO with Base44?

Yes, at two levels. Apps on Elite plans and up can offer sign-in through any OIDC identity provider – Google Workspace, Microsoft, GitHub, Okta and more. On enterprise workspaces, builders sign in with the organization's own SSO, and Enterprise admins can enforce it across every app in the workspace.

Does Base44 support two-factor authentication?

Yes. Turn on two-factor authentication with an authenticator app, or SMS on paid plans – Base44 then asks for your password and a verification code each time you sign in.

Can the AI change parts of my app I want protected?

You set the rules the AI follows in each app: add custom instructions, and freeze files or entities so the AI never modifies protected areas.

Build securely, from day one.