Security & Compliance

Safe, secure, and private.

Everything in base0 is engineered from the ground up to keep your agreements secure, compliant, and legally binding. Because your business is nobody else's business.

Certified Infrastructure

Our server and database hosting partners (AWS and NeonDB) are SOC 2 Type II certified. This ensures your documents are kept in highly secure environment data centers.

GDPR & DPDPA Ready

Fully compliant with Europe's GDPR and India's Digital Personal Data Protection Act (DPDPA) 2023. Our structured Data Processing Agreement (DPA) guarantees contractually backed compliance mechanisms.

Privacy by Design

We collect only the bare essential metadata required to execute legally binding e-signatures. We never sell, share, or monetize document contents or signer details to third parties.

ISO 27001 Infrastructure

Our server and hosting providers (AWS and NeonDB) are ISO/IEC 27001, 27017, and 27018 certified, featuring state-of-the-art physical security and redundant power controls.

Cryptographic Tamper-Evidence

Every signed document receives an automated SHA-256 cryptographic hash. If a signed document is modified by even a single pixel or character, the hash breaks, providing immediate legal evidence of tampering.

Comprehensive Audit Trails

Every event—document created, link opened, consent accepted, signing completed—is logged with timestamps, IP addresses, and device metadata. This creates an legally compliant audit log. See Terms of Service.

Secure Signer Verification

Signers are verified via unique, single-use tokenized URLs sent directly to their registered email or phone, preventing spoofing and ensuring authentic identity capture.

Explicit Consent Capture

Every signer is presented with a required consent screen to explicitly accept conducting the transaction electronically before accessing or signing documents.

Advanced Encryption Standards

All data is encrypted in transit using HTTPS and TLS 1.3. Documents and files stored in AWS S3, alongside our structured NeonDB PostgreSQL database records, are encrypted at rest using AES-256 keys.

Vetted Sub-Processors

We only transmit data to a small, highly vetted list of third-party sub-processors (like AWS, Resend, and Dodo Payments) that meet our rigorous security baselines. Read Exhibit B of our DPA.

Zero-Tracker Policy

We value your privacy. We do not run third-party advertising tracking, marketing cookies, or tracking pixels on our signature endpoints, preventing data leakage to external networks.

Role-Based Access (RBAC)

Admins can enforce strict workspace access levels, ensuring employees can only view or manage agreements matching their role permissions.

Need more information?

For custom setups, dedicated servers, or questions about our data safety practices, feel free to reach out to our team. We're here to help you get your agreements completed securely.