Compliance, covered
SOC 2 Type II

Independent audit of the design and operating effectiveness of our security controls.
ISO 27001

Certified information security management – the international standard.
GDPR

EU data protection standards, with a Data Processing Agreement available on request.
Your data, your rules
Control where your data lives, who can access it and whether it trains AI models.
Training data opt-outEnterprise
Opt your workspace's data out of AI model training.
Deleting your app's user data
Base44 supports a GDPR Deletion Flow to help you comply with users' right to erasure.
Your security, our priority.
We apply these practices at every stage – and independent auditors verify them.
Secure development life-cycle
Security runs through every stage of building Base44 – threat modeling, secure design, code reviews and penetration testing, so risks surface early and get fixed early.
Penetration testing
Internal teams and third-party firms test our defenses against real-world attack scenarios, based on OWASP methodologies. Our security team reviews, prioritizes and tracks every finding to resolution.
Encryption & key management
Base44 encrypts your app data in transit with TLS 1.2+ and at rest with AES-256, and manages secrets in a cloud key management service (KMS). Encryption covers backups too.
Secure payments & anti-fraud
Payments run through PCI DSS-certified providers. Base44 encrypts sensitive payment data in transit and never stores it, and a layered anti-fraud system combines specialized fraud-detection providers with Base44's own detection.
Third-party risk management
We assess every vendor against defined security and compliance requirements, and re-validate periodically. See the vendors that handle your data in the subprocessor directory below.
Bug bounty program
Independent security researchers probe our systems and disclose what they find – responsibly. Our security team reviews and validates every submission, prioritizes confirmed vulnerabilities by severity and fixes them.
Ask for an InviteDisaster Recovery & Business Continuity
We maintain defined Recovery Time and Recovery Point Objectives aligned with industry standards, backed by frequent automated backups and documented recovery procedures. Detailed commitments are available to Enterprise customers as part of their Service Level Agreement.
24/7 Security Monitoring
Our platform is monitored around the clock by a 24/7/365 Security Operations Center (SOC), powered by SIEM technology and supported by a dedicated security team.
Incident Response
A dedicated Security Incident Response Team operates under a formal Incident Response Plan and Security Incident Management Policy, ensuring security events are identified, contained, and resolved quickly.
Subprocessor directory
Third-party partners who help us securely process your data.
Security for every app
Every app built on Base44 comes with these controls:

Run a security scan from every app's Security tab. It checks for vulnerable third-party dependencies (SCA), insecure code patterns (SAST), exposed secrets, missing login checks and weak data access rules. Each finding comes with a severity rating and a plain explanation – and AI fixes it for you.
Workspace Security
Give every team a safe space to build.
Workspace roles
Owner, Editor and Viewer roles on every workspace – enterprise workspaces add Admin. Each role scopes what a builder can do, from full control to read-only.
Workspace authentication
Sign in to Base44 with Google, Apple or email and password – backed by anti-bot controls, email verification and optional 2-FA with an authenticator app, or SMS on paid plans. Organizations can sign-in with their SSO (OIDC) – Entra ID, Okta, Google, and more.
SSO enforcementEnterprise
Enterprises can enforce organizational SSO across every app built in the workspace.
Verified workspace domain
Verify your organization's domain with a DNS TXT record. Base44 uses it to enforce access policies and auto-onboard your team through SSO.
IP allowlistEnterprise
Restrict workspace and app access to specific networks – single IPs, CIDR ranges, IPv6 included. Requests from anywhere else get a 403.
Workspace security centerEnterprise
One place for workspace admins to scan and review security issues across every app in the workspace.
Workspace Governance & Monitoring
From who publishes to what each builder spends – every lever in admin hands, and the logs to prove it.
SCIM provisioningEnterprise
Run the full lifecycle from your IdP: create, update, deactivate and delete accounts and groups, with stable external-ID matching.
Role-based publishing controlEnterprise
Control who can publish and which visibility levels each role can use, with defaults applied across the workspace. Anyone blocked from publishing directly can send an approval request, so changes reach end users only through an approved path.
Connector managementEnterprise
Workspace admins control which connectors are available across every app, agent and Superagent. Enable or disable connectors workspace-wide – including shared and app-user connectors – and review which apps are affected before confirming a change.
Credit limitsEnterprise
Set a monthly credit limit per member. Spend stays predictable – and no single builder can burn through the budget.
Monitoring APIEnterprise
Pull workspace usage, health and analytics into your own tools through the Monitoring API – with workspace API keys that carry only the permissions you give them.
Audit logsEnterprise
A complete record of who did what across your workspace – sign-ins, publishing and governance events included. Stream events into your own monitoring tools through the Audit Logs API.





