EN · PL · DE · FR · IT · NL · ES

Partner attestation ≠ BaseCloud service certificate. We rely on qualified infrastructure partner assurance for physical and platform layers — without publishing partner identity on this public hub. See Infrastructure assurance and Control Inheritance Matrix.

Trust Hub · Compliance

Compliance & assurance

One catalogue with three assurance sources: BaseCloud-operated, inherited (provider scope), and shared. A provider ISO/SOC attestation is not a BaseCloud service certificate.

Jurisdiction overlays: Regulatory context. Marketing overview: Standards and compliance.

Third-party infrastructure assurance

When our infrastructure provider holds ISO/SOC/CSA attestations for contracted services, we use them as evidence for specific layers — subject to certificate scope, region and subservice organization treatment (inclusive vs carve-out).

Third-Party Infrastructure Assurance →

Cloud security controls (ISO 27017)

ISO 27001 ISMS baseline; ISO 27017 cloud themes split between provider (virtualization, DC) and BaseCloud (managed operations, tenant isolation operations).

Evidence tiers

  • Public — this catalogue, inheritance model, policies in Evidence
  • Customer — DPA, provider scope summaries, subprocessors, subservice org notes
  • NDA — full SOC reports, provider certificates, pen-test detail

Compliance requirements vary by jurisdiction, industry, customer configuration and use case. Nothing on this website constitutes legal advice. A provider certificate is evidence for the provider's scope — not automatic certification of the BaseCloud service. Certification is claimed only when evidence is listed as available for the defined scope.