Security

Security at Basepoint

Site lists, pro formas, interconnection studies, and data rooms are the business. This page sets out how Basepoint protects them, in the detail a security review needs.

Updated October 2026

Security overview

  • AES-256 encryption at rest, TLS 1.3 in transit
  • Tenant isolation enforced in the database on every table
  • Customer data is never used to train models
  • Private file storage with expiring signed links
  • Hosted on AWS, Vercel, and Supabase
  • Security questionnaire, DPA, and custom terms for Enterprise

Infrastructure

Basepoint runs on managed cloud infrastructure with the backend isolated from the public internet.

  • Managed cloud hostingThe application runs on Vercel. The database, authentication, and file storage run on Supabase, a managed Postgres service. The analysis engine, background workers, and data pipeline run as containers on Amazon ECS in AWS us-east-1.
  • Network isolationBackend services run in private security groups and are reachable only through a load balancer.
  • Secrets managementCredentials are held in AWS Secrets Manager and injected at run time. They are never stored in code.
  • Continuous monitoringAmazon CloudWatch alarms watch the backend services. Sentry tracks errors across the platform.

Data protection

Customer data is encrypted everywhere it rests and everywhere it moves, and files are never exposed on public URLs.

  • Encryption at restAES-256 across the database and file storage.
  • Encryption in transitTLS 1.3 for all traffic between your browser and Basepoint.
  • Managed key custodyEncryption keys are held by the hosting providers. No one at Basepoint handles key material.
  • Private object storageUploaded documents live in private buckets and are never served from a public URL.
  • Expiring signed linksFiles are reached through signed URLs that expire, issued only to people who already have access to the project.
  • Incident notificationIf a security incident affects your data, we notify you without undue delay with what happened, what data was involved, and what we did about it.

Access control

Every record belongs to a team, and that boundary is enforced by the database rather than by application code alone.

  • Authenticated accessEvery user signs in through Supabase Auth, with Google sign-in or email and password.
  • Tenant isolation at the databaseRow-level security on every table ties each record to its team. A request that bypasses the application still cannot read another team's data.
  • Role-based sharingProjects are shared by inviting a named person with a defined role. Nothing is shared by default.
  • External portal isolationClients and partners use a separate portal that shows only what is assigned to them. Portal links use random tokens, can carry an expiry date, and can be switched off.

AI governance

Models see the minimum needed to answer a request, and nothing you put into Basepoint is used to train them.

  • No training on customer dataYour data is never used to train models, by Basepoint or by any provider. Our providers process data sent through their APIs under commercial terms that exclude training.
  • Named providersAnthropic (Claude) for agents, document extraction, and chat. OpenAI for embeddings and some document reading. Some requests are routed through Vercel's AI Gateway.
  • Minimum necessary dataA provider receives the content of the request and nothing else from your workspace.
  • Reviewable outputAgent output lands in your workspace, where it can be reviewed, edited, or deleted like anything else.
  • Spend controlsAI usage is capped per team, with daily limits and alerts.

Confidential grid data

Utility data held under a confidentiality agreement, such as transmission base cases classified as Critical Energy Infrastructure Information (CEII), is handled under its own rules.

  • Segregated storageKept apart from the product database and readable only by the analysis engine.
  • No AI exposureNever sent to an AI model, including for debugging.
  • Derived results onlyUsers receive headroom, violations, and screening outcomes. They never receive the inputs.
  • Scrubbed diagnosticsError reports from the analysis engine are scrubbed before they leave it.

Data ownership

Your data is yours. It leaves in the formats your team already uses, and it is deleted when you ask.

  • Export on demandProjects, models, and documents export at any time as Excel, CSV, and shapefiles.
  • Deletion in the appProjects, sites, documents, and models can be deleted from inside the app.
  • Retention after closureWhen an account is closed, its data is kept for 30 days and then deleted. Earlier deletion is available on request.
  • No sale of personal informationWe do not sell personal information.

Documents and reviews

Everything a procurement review asks for, provided by the team that runs the platform.

  • Vendor security questionnaireCompleted in full for Enterprise plans.Request
  • Data processing agreementPublished, and available to countersign for Enterprise plans.View
  • Subprocessor listEvery provider that processes customer data on our behalf, and where it runs.View
  • Acceptable use policyWhat the platform may and may not be used for.View
  • Vulnerability disclosure policyScope, rules for testing, and what we commit to researchers.View
  • Service statusLive checks on the application and analysis engine, with incident history.View
  • Custom contract termsAgreed during the Enterprise security review.Request
  • Architecture walkthroughA working session with the engineers who built the platform, for your reviewers.Book
  • security.txtMachine-readable disclosure contact.View

Subprocessors

Every provider that processes customer data on our behalf, and what each one receives.

ProviderPurposeReceives
VercelApplication hostingApplication traffic and server-side requests
SupabaseDatabase, authentication, file storageCustomer data at rest
Amazon Web ServicesAnalysis engine, workers, data pipelineProject and site data used in analysis
AnthropicLanguage modelsThe content of each AI request
OpenAIEmbeddings and some document readingDocument text for each request
StripePayments and billingBilling contact and payment details
ResendTransactional emailEmail addresses and notification content
SentryError monitoringError reports and diagnostic context
GoogleSign-in, maps, Street View imagerySign-in identity, map and imagery requests

Map and parcel services (Regrid, Esri ArcGIS, CARTO, and OpenStreetMap Nominatim) receive the coordinates or addresses you search and nothing else. Integrations you connect yourself (Microsoft 365, Google Drive, Box, Dropbox, Smartsheet, HubSpot, Fireflies, and Granola) exchange data only after you authorize them from inside the app.

Responsible disclosure

If you find a security issue in Basepoint, email hello@getbasepoint.com with enough detail to reproduce it. We acknowledge every report, keep you updated while we fix it, and credit you if you want. Scope, rules for testing, and our commitments to researchers are in the vulnerability disclosure policy. Our security.txt carries the same contact.

Start your security review

Send us your questionnaire, or book a walkthrough with the engineers who built the platform.