Encrypted in transit and at rest
Every connection and every stored record is encrypted. Bank details are encrypted individually, per record, and never printed on a document that leaves the platform.
What protects your data, what the log keeps, how long we keep it, and what the AI can never do.
Data security
Every control below is in place today. The certifications that attest to them carry real dates, listed underneath.
Every connection and every stored record is encrypted. Bank details are encrypted individually, per record, and never printed on a document that leaves the platform.
Production signing and encryption keys live in a managed key service. Secrets never live in code or in configuration files.
Every table carrying fund data is scoped to the fund at the query layer, and the isolation is tested adversarially in every build.
Sanctions and PEP screening at onboarding and on an ongoing basis, with a daily rescreen of every investor on the register.
On the roadmap, with dates
Logs
An append-only audit trail is the platform's memory of what happened and who did it.
Money, ownership, documents, identity status: each change writes a row with the actor, the action, the entity, the value before and after, the timestamp and the request that caused it.
The log rejects edits and deletions for everyone, including Basis staff. A correction is a new row that says what it corrected.
The prompt version, the model, the inputs it read by reference, its output with citations, who approved or rejected it and what they changed, cost and latency.
An export for any period, per record, in open formats: for your auditor, your counsel, or an ODD questionnaire.
Data retention
Kept for the life of the fund, exportable at any time, and never held hostage.
The register and every record in it, including the historical activity an incoming provider needs to take over, in open formats. No exit fee, no extraction project.
Records of money, ownership and documents are retained as long as the fund exists on Basis. A document can be withdrawn only by a named person, and the log keeps the fact that it was.
Daily backups with a one-day recovery objective. Point-in-time recovery is on the roadmap above, with its date.
In-app notifications are kept for ninety days. The audit log, not the notification, is the durable record.
Agentic guardrails
There is no code path from a model's output to your register without a human's name on it.
Connections to Claude and to the API carry two scopes, read and propose. There is no approve or execute scope to grant, to anyone.
Citations for every field, a confidence, the model and the prompt version. Rejecting requires a written reason, and there is no bulk approve.
Text inside uploaded documents, emails and investor messages is never followed as an instruction. An output that looks like an instruction is flagged, not executed.
It never computes tax, characterizes income, values an asset, or sends anything to an investor. Where your agreement permits an override, it takes a written reason and a name; automated paths can never override.
Each agent can be disabled per fund. A disabled trigger writes a skipped-run record and never reaches the model.
A written summary of the controls above, the evidence format and the roadmap dates, prepared for operational due diligence questionnaires.
Twenty minutes on your own workflows, with your own structure on screen.
Tell us about your fund and where your investors are. We'll walk you through a global fund running on Basis, on your workflows.
Talk to us about migrating an existing fund
Prefer to pick a time? Book a walkthrough