For accounting firms there is no compromise when it comes to security

Basis is built with multiple layers of industry-standard security to protect your clients’ data. We’re SOC 2 Type II certified for Security, Availability, and Confidentiality.

Close-up view of a computer motherboard with visible circuits and components.
SOC 2 Type II Certified
ISO 27001 Compliant
ISO 42001 Compliant
GDPR coming soon
CCPA coming soon

AI Privacy

No model training

Your data never trains or improves any AI model.

Full data isolation

Strict tenant separation across every customer.

Traceable AI

Every agent action is logged and auditable.

No selling or sharing

Firm and client data is never shared with third parties.

Data deletion

Remove your data at any point.

Transparent by design

AI steps show sources, changes, and rationale.

Secure by Design

No credential storage

We never store your credentials. Access via revocable tokens only.

Encrypted at rest

AES-256 and HMAC across all stored data.

Encrypted in transit

HTTPS/TLS on every connection.

US-only hosting

All customer data stored in the United States.

Data segregation

Strict separation between customers with role-based access.

Multi-factor authentication

MFA enforced across all accounts.

Security Operations

Penetration testing

Regular third-party tests and vulnerability scanning.

Incident response

Rehearsed program with rapid triage and notification.

Encrypted backups

Daily backups with geographic redundancy.

Documentation & Compliance

SOC 2 Type II report

Available under NDA.

Additional documentation

Compliance docs available upon request.

Security contact

security@ofbasis.com