Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

Netbase security and compliance for software and AI: certified, practiced, clearly bounded

Netbase JSC holds ISO 27001 certification and a SOC 2 Type II attestation. On every project it runs secure code review, TLS in transit and AES at rest, role-based access control, MFA on admin dashboards, vulnerability scanning, penetration testing and disaster recovery, and it follows GDPR, HIPAA-aligned and CCPA practices where your product needs them. AI work runs under the same rules, with approved tools and human review.

Start a security conversation View our work

Reviewed by David (CEO) · Updated 17 Sep 2026

star

Certifications and compliance at a glance

  • ISO 27001

    Certified
    What it covers, in the published wording
    Structured information security management
  • SOC 2 Type II

    Attested
    What it covers, in the published wording
    Secure SaaS operations and data controls
  • GDPR

    Aligned practice
    What it covers, in the published wording
    Data privacy in Europe
  • HIPAA

    HIPAA-aligned methodologies
    What it covers, in the published wording
    Healthcare data handling
  • CCPA

    Compliance practice
    What it covers, in the published wording
    Clients with U.S. customer bases

ISO 27001 and SOC 2 Type II are the two formal credentials. GDPR, HIPAA and CCPA are laws, not certificates, so for those Netbase states the practices it follows rather than a credential it holds. For its own AI delivery practice, Netbase applies the ISO/IEC 42001 AI management system framework.

This page does not publish certificate or report numbers, issue or expiry dates, the auditor or certification body, or the audit scope. If your vendor review needs those details, request them from Netbase during due diligence.

What the two credentials mean for a buyer

  • ISO 27001

    Netbase runs a structured information security management system, certified against ISO 27001. For you, that means security is run as a managed system, not left to individual engineers.

  • SOC 2 Type II

    SOC 2 is the AICPA reporting framework for examining controls at a service organization that are relevant to security, availability, processing integrity, confidentiality or privacy. Netbase holds a SOC 2 Type II attestation for secure SaaS operations and data controls, which matters most when Netbase builds or runs a SaaS platform for you.

The practices at a glance

  • Code and change

    Secure code review and version control

  • Data in transit

    TLS encryption

  • Data at rest

    AES encryption

  • Access

    Role-based access control (RBAC), so people see only what their role needs

  • Admin accounts

    Multi-factor authentication (MFA) on admin dashboards

  • Weakness discovery

    Vulnerability scanning and penetration testing

  • Resilience

    Disaster recovery planning

  • People

    Contributors work under NDA

  • Contracts

    NDAs, data processing agreements (DPAs) and service level agreements (SLAs) on request

Security by design and DevSecOps, from the first commit

Security is part of the build itself, not a last-week check: requirements are set in discovery and architecture planning, and the checks below run inside every Agile increment, including for APIs and AI features.

  • Code review and version control

    Every change goes through version control and a security-minded code review before it ships, giving you a full history of what changed, when and by whom.

  • Encryption by default

    Data in transit travels over TLS; data stored by the application is AES-encrypted.

  • Least-privilege access

    Role-based access control keeps permissions tied to roles, not to individuals collecting rights over time, and admin dashboards sit behind MFA.

  • Finding weaknesses before attackers do

    Vulnerability scanning and penetration testing look for the problems that code review misses.

  • Planning for the bad day

    Disaster recovery planning means an outage or data loss has a planned path back, not an improvised one.

These practices come with every custom software development engagement. For a product Netbase builds and operates itself, see the Printcart web-to-print SaaS record.

AI governance: security by design for AI features and AI-assisted delivery

AI adds new data paths, so Netbase treats it as part of the security design, not an add-on, under the AI management practice named above.

  • Approved tools only

    Engineers use the AI tools you approve for your code and data, chosen per project; AI suggestions go through the same code review as any other change.

  • Your data stays yours

    Client data is not used to train AI models without your agreement, and data handling can be written into the NDA and DPA.

  • AI features built to be checked

    Retrieval respects user permissions, model inputs and outputs are logged within agreed data rules, and features are tested against prompt injection and data leakage before release.

  • A person decides

    AI drafts, suggests or flags; a named person approves anything that changes production, money or customer records.

Shared responsibility: where our part ends and yours begins

Security is never one party's job, and a vendor's certification does not certify the product it builds for you.

  • Application code

    Netbase is responsible for
    Secure review, version control and fixing issues found in the code Netbase writes
    You are responsible for
    Approving releases and reporting issues your users see
  • Access

    Netbase is responsible for
    RBAC design and MFA on admin dashboards Netbase builds
    You are responsible for
    Deciding who gets which role, and removing leavers promptly
  • Data

    Netbase is responsible for
    Encryption in transit and at rest within the delivered system
    You are responsible for
    Deciding what data is collected, and your lawful basis for it
  • Testing

    Netbase is responsible for
    Vulnerability scanning and penetration testing in the agreed scope
    You are responsible for
    Sharing known risks and approving test windows
  • Recovery

    Netbase is responsible for
    Disaster recovery planning for the delivered system
    You are responsible for
    Your business continuity plan around it
  • Contracts

    Netbase is responsible for
    Signing NDAs, DPAs and SLAs when you request them
    You are responsible for
    Stating your regulatory requirements up front

Exact scope, response terms and hosting responsibilities are set per engagement in the contract, not assumed from this table.

Privacy and sector obligations: GDPR, HIPAA and CCPA

For products serving people in the European Union, patients in the United States or California residents, the law shapes how personal data is handled, and Netbase follows the matching practice.

  • GDPR

    Netbase aligns its delivery with GDPR for data privacy in Europe. Under Article 28(3) of the EU General Data Protection Regulation, processing by a processor on behalf of a controller must be governed by a contract or other binding legal act, so Netbase signs a DPA on request to cover that relationship.

  • HIPAA

    For healthcare data handling, Netbase applies HIPAA-aligned methodologies.

  • CCPA

    Netbase supports CCPA compliance for clients with U.S. customer bases. The California Consumer Privacy Act gives California residents rights such as the right to know, to delete and to opt out of the sale or sharing of their personal information, and Netbase can build the features your compliance plan needs.

Your legal team still decides what your obligations are. Netbase provides engineering, not legal advice, and following a practice is not a guarantee that your product is compliant.

Your data and your IP across the project lifecycle

  • Before work starts

    NDAs protect what you share during discovery, and every contributor works under NDA.

  • During delivery

    The controls above apply to every change.

  • Ownership

    For custom development, you own the IP created for you. Netbase productized modules and Business Division products are licensed to you, not transferred. Reused building blocks, such as those in the SaaS product accelerator, stay under license while your custom code stays yours.

  • After delivery

    Support and incident terms are agreed in an SLA when you request one.

Start a security conversation

Have a security questionnaire, a DPA template or a list of controls your auditors expect? Start a security conversation with Netbase and bring it along, with any certificate details your review needs. See what Netbase has delivered in our work, and the rest of the trust record under Why Netbase.

Contact Netbase

Discuss a project

Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.
Project enquiries

[email protected]

WhatsApp

+84 937 869 689

Office address

91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam

Get in touch

Tell us what you want to build, modernize, or operate.

Tell us what you want to build, modernize, or operate.

Contact Netbase