Security you can build on

Every app built on Base44 comes with AES-256 encryption, built-in security scans and AI-powered fixes – backed by SOC 2 Type II and ISO 27001 certification.

Compliance, covered

SOC 2 Type II

SOC 2 Type II logo

Independent audit of the design and operating effectiveness of our security controls.

ISO 27001

ISO 27001 logo

Certified information security management – the international standard.

View Certification

GDPR

GDPR logo

EU data protection standards, with a Data Processing Agreement available on request.

Overview

Your data, your rules

Control where your data lives, who can access it and whether it trains AI models.

Data residency

Choose the region where your app data is stored.

Learn more

Training data opt-outEnterprise

Opt your workspace's data out of AI model training.

Deleting your app's user data

Base44 supports a GDPR Deletion Flow to help you comply with users' right to erasure.

Your security, our priority.

We apply these practices at every stage – and independent auditors verify them.

Secure development life-cycle

Security runs through every stage of building Base44 – threat modeling, secure design, code reviews and penetration testing, so risks surface early and get fixed early.

Penetration testing

Internal teams and third-party firms test our defenses against real-world attack scenarios, based on OWASP methodologies. Our security team reviews, prioritizes and tracks every finding to resolution.

Encryption & key management

Base44 encrypts your app data in transit with TLS 1.2+ and at rest with AES-256, and manages secrets in a cloud key management service (KMS). Encryption covers backups too.

Secure payments & anti-fraud

Payments run through PCI DSS-certified providers. Base44 encrypts sensitive payment data in transit and never stores it, and a layered anti-fraud system combines specialized fraud-detection providers with Base44's own detection.

Third-party risk management

We assess every vendor against defined security and compliance requirements, and re-validate periodically. See the vendors that handle your data in the subprocessor directory below.

Bug bounty program

Independent security researchers probe our systems and disclose what they find – responsibly. Our security team reviews and validates every submission, prioritizes confirmed vulnerabilities by severity and fixes them.

Ask for an Invite

Disaster Recovery & Business Continuity

We maintain defined Recovery Time and Recovery Point Objectives aligned with industry standards, backed by frequent automated backups and documented recovery procedures. Detailed commitments are available to Enterprise customers as part of their Service Level Agreement.

24/7 Security Monitoring

Our platform is monitored around the clock by a 24/7/365 Security Operations Center (SOC), powered by SIEM technology and supported by a dedicated security team.

Incident Response

A dedicated Security Incident Response Team operates under a formal Incident Response Plan and Security Incident Management Policy, ensuring security events are identified, contained, and resolved quickly.

Subprocessor directory

Third-party partners who help us securely process your data.

  • Mongo (US)

    Data storage and hosting

  • SendGrid (US)

    Email transmission and external communication

  • Render (US)

    Server services

  • GCP - Google cloud (US)

    Analytics services

  • OpenAI (US)

    API calls to LLM

  • Anthropic (US)

    API calls to LLM

  • Wix.com Ltd. (IL)

    Providing and improving the services

  • Datadog (US)

    General logging purposes

  • Langfuse (DE)

    LLM logging

  • Logfire (UK)

    General logging purposes

Security for every app

Every app built on Base44 comes with these controls:

A team collaborating around a table, with a Base44-built task-status dashboard.

Run a security scan from every app's Security tab. It checks for vulnerable third-party dependencies (SCA), insecure code patterns (SAST), exposed secrets, missing login checks and weak data access rules. Each finding comes with a severity rating and a plain explanation – and AI fixes it for you.

Workspace Security

Give every team a safe space to build.

  • Workspace roles

    Owner, Editor and Viewer roles on every workspace – enterprise workspaces add Admin. Each role scopes what a builder can do, from full control to read-only.

  • Workspace authentication

    Sign in to Base44 with Google, Apple or email and password – backed by anti-bot controls, email verification and optional 2-FA with an authenticator app, or SMS on paid plans. Organizations can sign-in with their SSO (OIDC) – Entra ID, Okta, Google, and more.

  • SSO enforcement

    Enterprise

    Enterprises can enforce organizational SSO across every app built in the workspace.

  • Verified workspace domain

    Verify your organization's domain with a DNS TXT record. Base44 uses it to enforce access policies and auto-onboard your team through SSO.

  • IP allowlist

    Enterprise

    Restrict workspace and app access to specific networks – single IPs, CIDR ranges, IPv6 included. Requests from anywhere else get a 403.

  • Workspace security center

    Enterprise

    One place for workspace admins to scan and review security issues across every app in the workspace.

Workspace Governance & Monitoring

From who publishes to what each builder spends – every lever in admin hands, and the logs to prove it.

  1. Enterprise

    SCIM provisioning

    Run the full lifecycle from your IdP: create, update, deactivate and delete accounts and groups, with stable external-ID matching.

  2. Enterprise

    Role-based publishing control

    Control who can publish and which visibility levels each role can use, with defaults applied across the workspace. Anyone blocked from publishing directly can send an approval request, so changes reach end users only through an approved path.

  3. Enterprise

    Connector management

    Workspace admins control which connectors are available across every app, agent and Superagent. Enable or disable connectors workspace-wide – including shared and app-user connectors – and review which apps are affected before confirming a change.

  4. Enterprise

    Credit limits

    Set a monthly credit limit per member. Spend stays predictable – and no single builder can burn through the budget.

  5. Enterprise

    Monitoring API

    Pull workspace usage, health and analytics into your own tools through the Monitoring API – with workspace API keys that carry only the permissions you give them.

  6. Enterprise

    Audit logs

    A complete record of who did what across your workspace – sign-ins, publishing and governance events included. Stream events into your own monitoring tools through the Audit Logs API.

The questions security reviews ask.

Base44 is SOC 2 Type II and ISO 27001 certified, GDPR compliant and independently penetration-tested. Every app comes with built-in security scans, row-level security and encrypted secrets – and enterprise workspaces add SSO enforcement, IP allowlists, full audit logs and more.

Build securely, from day one.

Start Building