Security you can build on

Every app built on Base44 comes with AES-256 encryption, built-in security scans and AI-powered fixes – backed by SOC 2 Type II and ISO 27001 certification.

Compliance, covered

SOC 2 Type II

SOC 2 Type II logo

Independent audit of the design and operating effectiveness of our security controls.

ISO 27001

ISO 27001 logo

Certified information security management – the international standard.

GDPR

GDPR logo

EU data protection standards, with a Data Processing Agreement available on request.

Your data, your rules

Control where your data lives, who can access it and whether it trains AI models.

Data residency

Choose the region where your app data is stored.

Learn more

Training data opt-outEnterprise

Opt your workspace's data out of AI model training.

Deleting your app's user data

Base44 supports a GDPR Deletion Flow to help you comply with users' right to erasure.

Your security, our priority.

We apply these practices at every stage – and independent auditors verify them.

Secure development life-cycle

Security runs through every stage of building Base44 – threat modeling, secure design, code reviews and penetration testing, so risks surface early and get fixed early.

Penetration testing

Internal teams and third-party firms test our defenses against real-world attack scenarios, based on OWASP methodologies. Our security team reviews, prioritizes and tracks every finding to resolution.

Encryption & key management

Base44 encrypts your app data in transit with TLS 1.2+ and at rest with AES-256, and manages secrets in a cloud key management service (KMS). Encryption covers backups too.

Secure payments & anti-fraud

Payments run through PCI DSS-certified providers. Base44 encrypts sensitive payment data in transit and never stores it, and a layered anti-fraud system combines specialized fraud-detection providers with Base44's own detection.

Third-party risk management

We assess every vendor against defined security and compliance requirements, and re-validate periodically. See the vendors that handle your data in the subprocessor directory below.

Bug bounty program

Independent security researchers probe our systems and disclose what they find – responsibly. Our security team reviews and validates every submission, prioritizes confirmed vulnerabilities by severity and fixes them.

Ask for an Invite

Disaster Recovery & Business Continuity

We maintain defined Recovery Time and Recovery Point Objectives aligned with industry standards, backed by frequent automated backups and documented recovery procedures. Detailed commitments are available to Enterprise customers as part of their Service Level Agreement.

24/7 Security Monitoring

Our platform is monitored around the clock by a 24/7/365 Security Operations Center (SOC), powered by SIEM technology and supported by a dedicated security team.

Incident Response

A dedicated Security Incident Response Team operates under a formal Incident Response Plan and Security Incident Management Policy, ensuring security events are identified, contained, and resolved quickly.

Subprocessor directory

Third-party partners who help us securely process your data.

View all

Mongo

Data storage and hosting

Country

US

SendGrid

Email transmission and external communication

Country

US

Render

Server services

Country

US

GCP - Google cloud

Analytics services

Country

US

OpenAI

API calls to LLM

Country

US

Anthropic

API calls to LLM

Country

US

Wix.com Ltd.

Providing and improving the services

Country

Israel

DataDog

General logging purposes

Country

US

Langfuse

LLM logging

Country

Germany

Logfire

General logging purposes

Country

UK

Security for every app

Every app built on Base44 comes with these controls:

A team collaborating around a table, with a Base44-built task-status dashboard.

Run a security scan from every app's Security tab. It checks for vulnerable third-party dependencies (SCA), insecure code patterns (SAST), exposed secrets, missing login checks and weak data access rules. Each finding comes with a severity rating and a plain explanation – and AI fixes it for you.

Workspace Security

Give every team a safe space to build.

Workspace roles

Owner, Editor and Viewer roles on every workspace – enterprise workspaces add Admin. Each role scopes what a builder can do, from full control to read-only.

Workspace authentication

Sign in to Base44 with Google, Apple or email and password – backed by anti-bot controls, email verification and optional 2-FA with an authenticator app, or SMS on paid plans. Organizations can sign-in with their SSO (OIDC) – Entra ID, Okta, Google, and more.

SSO enforcementEnterprise

Enterprises can enforce organizational SSO across every app built in the workspace.

Verified workspace domain

Verify your organization's domain with a DNS TXT record. Base44 uses it to enforce access policies and auto-onboard your team through SSO.

IP allowlistEnterprise

Restrict workspace and app access to specific networks – single IPs, CIDR ranges, IPv6 included. Requests from anywhere else get a 403.

Workspace security centerEnterprise

One place for workspace admins to scan and review security issues across every app in the workspace.

Workspace Governance & Monitoring

From who publishes to what each builder spends – every lever in admin hands, and the logs to prove it.

SCIM provisioningEnterprise

Run the full lifecycle from your IdP: create, update, deactivate and delete accounts and groups, with stable external-ID matching.

Role-based publishing controlEnterprise

Control who can publish and which visibility levels each role can use, with defaults applied across the workspace. Anyone blocked from publishing directly can send an approval request, so changes reach end users only through an approved path.

Connector managementEnterprise

Workspace admins control which connectors are available across every app, agent and Superagent. Enable or disable connectors workspace-wide – including shared and app-user connectors – and review which apps are affected before confirming a change.

Credit limitsEnterprise

Set a monthly credit limit per member. Spend stays predictable – and no single builder can burn through the budget.

Monitoring APIEnterprise

Pull workspace usage, health and analytics into your own tools through the Monitoring API – with workspace API keys that carry only the permissions you give them.

Audit logsEnterprise

A complete record of who did what across your workspace – sign-ins, publishing and governance events included. Stream events into your own monitoring tools through the Audit Logs API.

The questions security reviews ask.

Base44 is SOC 2 Type II and ISO 27001 certified, GDPR compliant and independently penetration-tested. Every app comes with built-in security scans, row-level security and encrypted secrets – and enterprise workspaces add SSO enforcement, IP allowlists, full audit logs and more.

Build securely, from day one.

Start Building