Trust Hub · Compliance
Compliance & assurance
One catalogue with three assurance sources: BaseCloud-operated, inherited (provider scope), and shared. A provider ISO/SOC attestation is not a BaseCloud service certificate.
Jurisdiction overlays: Regulatory context. Marketing overview: Standards and compliance.
Third-party infrastructure assurance
When our infrastructure provider holds ISO/SOC/CSA attestations for contracted services, we use them as evidence for specific layers — subject to certificate scope, region and subservice organization treatment (inclusive vs carve-out).
Third-Party Infrastructure Assurance →
Cloud security controls (ISO 27017)
ISO 27001 ISMS baseline; ISO 27017 cloud themes split between provider (virtualization, DC) and BaseCloud (managed operations, tenant isolation operations).
Evidence tiers
- Public — this catalogue, inheritance model, policies in Evidence
- Customer — DPA, provider scope summaries, subprocessors, subservice org notes
- NDA — full SOC reports, provider certificates, pen-test detail
Compliance requirements vary by jurisdiction, industry, customer configuration and use case. Nothing on this website constitutes legal advice. A provider certificate is evidence for the provider's scope — not automatic certification of the BaseCloud service. Certification is claimed only when evidence is listed as available for the defined scope.