Security
Security that layers on — never bypasses.
Basicloud adds its own enforcement on top of your system's permissions. It never weakens what you already have.
01 · The controls
Six layers, on by default.
Multi-tenant isolation
Every tenant's configuration, sessions, and data access are fully isolated from every other tenant's.
Row-level access control
Sharing and ownership rules are enforced inside every query — layered on top of your source system's own permissions.
Two-factor authentication
Accounts are protected with two-factor authentication.
Encrypted tokens
OAuth tokens are encrypted at rest and never exposed to the browser.
httpOnly-cookie auth
Sessions ride in httpOnly cookies — no tokens in localStorage, nothing for scripts to steal.
Audit trails
Sensitive actions are logged, so you always know who did what — and when.
02 · How access is enforced
Every request passes three gates.
GATE 1
Tenant
The request is resolved to exactly one tenant. Configuration, sessions, and data access never cross that boundary.
GATE 2
Role
The user's role decides which objects, layouts, and modules exist for them at all — customers, partners, and employees see different portals.
GATE 3
Row
Sharing and ownership rules are compiled into the query itself — records outside a user's scope are never fetched, not just hidden.
03 · Where your data lives
Your records never leave your system.
Basicloud stores none of your records. Record data stays in your connected system and is read live on every request; we keep only what's needed to run your portal.
Found a vulnerability or need our security details for a review? Write to hello@basicloud.ai.