Security & Compliance
Built for sensitive operations, not just logins.
BaseOps is designed for municipal operations where privacy, auditability, and uptime are non-negotiable. We combine encryption, role-based access, audit trails, and clear incident response so you can move your workflows online with confidence.
Security-first operations
Encryption, access control, and audit logs wired into the core.
Data protection
Encryption and data handling by default, not as an add-on.
BaseOps is designed with encryption and clear data boundaries, so sensitive records don’t end up scattered across inboxes and shared drives.
Encryption in transit & at rest
All access to BaseOps is secured via HTTPS/TLS. Data is stored in encrypted databases and encrypted backups managed by our hosting provider.
- • TLS for all web traffic.
- • Encrypted database storage.
- • Encrypted backups for disaster recovery.
Handling SSNs & sensitive fields
Fields that may contain Social Security Numbers or similar identifiers are handled separately and can be redacted in PDFs and views by default.
- • Segregated storage for sensitive fields.
- • Redacted by default in PDFs & standard views.
- • Full views require additional permissions and are logged.
Data separation by tenant
BaseOps is built for multi-tenant use. Each tenant’s data is logically isolated, and cross-tenant access is restricted to authorized system operations only.
- • Tenant IDs on every record.
- • Access and APIs scoped per tenant.
- • Super Admin tools respect clear tenant boundaries.
Access & permissions
Role-based access aligned to how your teams actually work.
BaseOps uses role-based access controls so you can give your team the tools they need — without granting full-database visibility to every user.
- Super Admin: Tenant and system configuration, module settings, and cross-tenant insights.
- Tenant Admin: Department configuration, user management, and day-to-day operations.
- Member: Access to forms, logbooks, and tools they need — nothing more.
Audit trails & monitoring
Key actions in BaseOps are logged, including form submissions, status changes, and administrative activity, so you can answer “who changed what and when?” without digging through email.
- • Changes to form statuses and approvals.
- • Access to sensitive fields (like SSNs) where configured.
- • User role changes and configuration updates.
Admin monitoring for compliance
BaseOps supports admin monitoring modes, focused on metadata and operational health — not reading confidential staff conversations unless legally required and properly authorized.
Reliability & incident response
Designed for uptime, with a clear plan when something goes wrong.
No platform is perfect, but you should know how issues are handled. BaseOps gives you transparency into current status, planned maintenance, and how we respond to incidents.
Uptime & monitoring
The BaseOps application and key services are monitored so we can detect and respond to issues quickly. We aim for high availability appropriate to municipal workflows.
You can always see current platform health on our Status page.
Backups & recovery
Data is backed up regularly, with retention windows designed for operational recovery in the event of a major failure.
- • Regular database backups.
- • Multiple restore points.
- • Documented recovery procedures.
Incident response
In the event of a security or availability incident, we focus on quick containment, transparent communication, and prevention of recurrence.
- • Identify & contain the issue.
- • Communicate impact and status updates.
- • Post-incident review and safeguards.
Compliance posture
Built with public records and municipal compliance in mind.
BaseOps is designed to support public records responsibilities and internal policy requirements, even as formal certifications evolve over time.
- • Clear data retention settings across modules.
- • Auditability for key operational and access events.
- • Separation of public and internal-only information.
Reporting a security concern
If you believe you’ve found a security issue in BaseOps, we want to hear about it. Please avoid sharing sensitive information in unencrypted channels.
- Email: security@baseops.app
- Include a description of the issue and how it can be reproduced.
- We review and respond to good-faith reports as quickly as possible.
Talk with us
Need to run BaseOps by your IT or legal team?
We’re happy to walk through our architecture, security controls, and roadmap so your team can evaluate BaseOps with full context.