Trust Hub · Security
Security architecture
How BaseCloud protects the physical, virtualization and management planes so customers can build on a controlled IaaS foundation.
Tenant isolation
Customer workloads are separated at the virtualization and network layers. Administrative access to the host and hypervisor is restricted to BaseCloud operators under MFA and RBAC. Guest OS and application isolation remain customer-controlled unless a managed operating model is contracted.
Identity and privileged access
Operator access uses role-based controls, MFA, session logging and least privilege. Customer IAM inside VMs and applications is the customer’s responsibility (see shared responsibility).
Encryption
Encryption in transit for management and customer-facing control channels; encryption at rest for platform-managed storage where offered. Key management for guest-level crypto is typically customer-owned unless included in the managed package.
Monitoring
24/7 infrastructure and security monitoring for the BaseCloud-operated layers: hosts, hypervisors, network edge and backup jobs. Customer application telemetry is optional / contracted.
Vulnerability management
Regular scanning and patching of BaseCloud-managed hosts and control-plane components. Guest OS patching follows the agreed operating model (customer or BaseCloud).
Incident response
24/7 escalation path for infrastructure and security incidents affecting BaseCloud layers. Customer notification follows contractual terms. Public vulnerability reports: Vulnerability Disclosure Policy.
Public vs gated
- Public — this page, VDP, high-level architecture.
- Customer / NDA — detailed diagrams, IR runbook excerpts, pen-test summaries via the security package.
Compliance requirements vary by jurisdiction, industry, customer configuration and use case. Nothing on this website constitutes legal advice. A provider certificate is evidence for the provider's scope — not automatic certification of the BaseCloud service. Certification is claimed only when evidence is listed as available for the defined scope.