Skip to content

Security

Security that layers on — never bypasses.

Basicloud adds its own enforcement on top of your system's permissions. It never weakens what you already have.

01 · The controls

Six layers, on by default.

Multi-tenant isolation

Every tenant's configuration, sessions, and data access are fully isolated from every other tenant's.

Row-level access control

Sharing and ownership rules are enforced inside every query — layered on top of your source system's own permissions.

Two-factor authentication

Accounts are protected with two-factor authentication.

Encrypted tokens

OAuth tokens are encrypted at rest and never exposed to the browser.

httpOnly-cookie auth

Sessions ride in httpOnly cookies — no tokens in localStorage, nothing for scripts to steal.

Audit trails

Sensitive actions are logged, so you always know who did what — and when.

02 · How access is enforced

Every request passes three gates.

GATE 1

Tenant

The request is resolved to exactly one tenant. Configuration, sessions, and data access never cross that boundary.

GATE 2

Role

The user's role decides which objects, layouts, and modules exist for them at all — customers, partners, and employees see different portals.

GATE 3

Row

Sharing and ownership rules are compiled into the query itself — records outside a user's scope are never fetched, not just hidden.

One dataset in your system; a row-level filter scopes every query, so each customer or partner receives only their own records.

03 · Where your data lives

Your records never leave your system.

Basicloud stores none of your records. Record data stays in your connected system and is read live on every request; we keep only what's needed to run your portal.

Record data
Stays in your system (e.g. Salesforce). Read live through the connection — never copied, synced, or stored by Basicloud.
What we store
Portal configuration — connected objects, layouts, sharing rules, branding, and portal users — plus audit logs.
Hosting
Google Cloud Platform, region us-central1 (Iowa, USA).
Encryption
TLS in transit. Encrypted at rest on Google Cloud; OAuth tokens are additionally encrypted and never sent to the browser.
Subprocessors
Google Cloud Platform (hosting).
Disconnecting
Revoke the OAuth grant and portal access to your system ends — there is no copy of your records left behind.

Found a vulnerability or need our security details for a review? Write to hello@basicloud.ai.

Bring your security questions to the demo.