Questions for security reviews: security@baseshift.com
1. Our security principles
Least privilege by default. Customer data stays in the environments you control whenever you choose self-hosted or on-prem deployment. Masking and subsetting are first-class so development and agent workflows can use realistic data without exposing sensitive production values.
2. Deployment options
Baseshift Cloud: managed control plane with encrypted storage and network isolation for clones and snapshots.
Self-hosted / on-prem / BYOC: run Baseshift in your cloud or data center so source data never leaves your network. You keep ownership of infrastructure, keys, and network boundaries. When installed on-prem your data is never sent to Baseshift.
3. Data protection
Encryption in transit (TLS) for application and agent connections.
Encryption at rest for stored snapshots and sensitive configuration where Baseshift manages storage.
Configurable masking policies so personally identifiable and sensitive fields can be anonymized before data is used in non-production environments.
Isolated, writable clones so developers and agents work in sandboxes rather than shared staging or production.
4. Compliance
SOC 2 Type II: Baseshift is SOC 2 Type II certified and maintains a report covering the security of its systems and controls.
ISO 27001: Baseshift is ISO 27001 certified for our information security management system.
We can share our SOC 2 Type II report, ISO 27001 certificate, and security questionnaires under NDA for qualified prospects. Contact security@baseshift.com or your Baseshift representative.
Last updated: August 2026.
