Certifications and compliance at a glance
-
ISO 27001
Certified- What it covers, in the published wording
- Structured information security management
-
SOC 2 Type II
Attested- What it covers, in the published wording
- Secure SaaS operations and data controls
-
GDPR
Aligned practice- What it covers, in the published wording
- Data privacy in Europe
-
HIPAA
HIPAA-aligned methodologies- What it covers, in the published wording
- Healthcare data handling
-
CCPA
Compliance practice- What it covers, in the published wording
- Clients with U.S. customer bases
ISO 27001 and SOC 2 Type II are the two formal credentials. GDPR, HIPAA and CCPA are laws, not certificates, so for those Netbase states the practices it follows rather than a credential it holds. For its own AI delivery practice, Netbase applies the ISO/IEC 42001 AI management system framework.
This page does not publish certificate or report numbers, issue or expiry dates, the auditor or certification body, or the audit scope. If your vendor review needs those details, request them from Netbase during due diligence.
What the two credentials mean for a buyer
-
ISO 27001
Netbase runs a structured information security management system, certified against ISO 27001. For you, that means security is run as a managed system, not left to individual engineers.
-
SOC 2 Type II
SOC 2 is the AICPA reporting framework for examining controls at a service organization that are relevant to security, availability, processing integrity, confidentiality or privacy. Netbase holds a SOC 2 Type II attestation for secure SaaS operations and data controls, which matters most when Netbase builds or runs a SaaS platform for you.
The practices at a glance
-
Code and change
Secure code review and version control
-
Data in transit
TLS encryption
-
Data at rest
AES encryption
-
Access
Role-based access control (RBAC), so people see only what their role needs
-
Admin accounts
Multi-factor authentication (MFA) on admin dashboards
-
Weakness discovery
Vulnerability scanning and penetration testing
-
Resilience
Disaster recovery planning
-
People
Contributors work under NDA
-
Contracts
NDAs, data processing agreements (DPAs) and service level agreements (SLAs) on request
Security by design and DevSecOps, from the first commit
Security is part of the build itself, not a last-week check: requirements are set in discovery and architecture planning, and the checks below run inside every Agile increment, including for APIs and AI features.
-
Code review and version control
Every change goes through version control and a security-minded code review before it ships, giving you a full history of what changed, when and by whom.
-
Encryption by default
Data in transit travels over TLS; data stored by the application is AES-encrypted.
-
Least-privilege access
Role-based access control keeps permissions tied to roles, not to individuals collecting rights over time, and admin dashboards sit behind MFA.
-
Finding weaknesses before attackers do
Vulnerability scanning and penetration testing look for the problems that code review misses.
-
Planning for the bad day
Disaster recovery planning means an outage or data loss has a planned path back, not an improvised one.
These practices come with every custom software development engagement. For a product Netbase builds and operates itself, see the Printcart web-to-print SaaS record.
AI governance: security by design for AI features and AI-assisted delivery
AI adds new data paths, so Netbase treats it as part of the security design, not an add-on, under the AI management practice named above.
-
Approved tools only
Engineers use the AI tools you approve for your code and data, chosen per project; AI suggestions go through the same code review as any other change.
-
Your data stays yours
Client data is not used to train AI models without your agreement, and data handling can be written into the NDA and DPA.
-
AI features built to be checked
Retrieval respects user permissions, model inputs and outputs are logged within agreed data rules, and features are tested against prompt injection and data leakage before release.
-
A person decides
AI drafts, suggests or flags; a named person approves anything that changes production, money or customer records.
Shared responsibility: where our part ends and yours begins
Security is never one party's job, and a vendor's certification does not certify the product it builds for you.
-
Application code
- Netbase is responsible for
- Secure review, version control and fixing issues found in the code Netbase writes
- You are responsible for
- Approving releases and reporting issues your users see
-
Access
- Netbase is responsible for
- RBAC design and MFA on admin dashboards Netbase builds
- You are responsible for
- Deciding who gets which role, and removing leavers promptly
-
Data
- Netbase is responsible for
- Encryption in transit and at rest within the delivered system
- You are responsible for
- Deciding what data is collected, and your lawful basis for it
-
Testing
- Netbase is responsible for
- Vulnerability scanning and penetration testing in the agreed scope
- You are responsible for
- Sharing known risks and approving test windows
-
Recovery
- Netbase is responsible for
- Disaster recovery planning for the delivered system
- You are responsible for
- Your business continuity plan around it
-
Contracts
- Netbase is responsible for
- Signing NDAs, DPAs and SLAs when you request them
- You are responsible for
- Stating your regulatory requirements up front
Exact scope, response terms and hosting responsibilities are set per engagement in the contract, not assumed from this table.
Privacy and sector obligations: GDPR, HIPAA and CCPA
For products serving people in the European Union, patients in the United States or California residents, the law shapes how personal data is handled, and Netbase follows the matching practice.
-
GDPR
Netbase aligns its delivery with GDPR for data privacy in Europe. Under Article 28(3) of the EU General Data Protection Regulation, processing by a processor on behalf of a controller must be governed by a contract or other binding legal act, so Netbase signs a DPA on request to cover that relationship.
-
HIPAA
For healthcare data handling, Netbase applies HIPAA-aligned methodologies.
-
CCPA
Netbase supports CCPA compliance for clients with U.S. customer bases. The California Consumer Privacy Act gives California residents rights such as the right to know, to delete and to opt out of the sale or sharing of their personal information, and Netbase can build the features your compliance plan needs.
Your legal team still decides what your obligations are. Netbase provides engineering, not legal advice, and following a practice is not a guarantee that your product is compliant.
Your data and your IP across the project lifecycle
-
Before work starts
NDAs protect what you share during discovery, and every contributor works under NDA.
-
During delivery
The controls above apply to every change.
-
Ownership
For custom development, you own the IP created for you. Netbase productized modules and Business Division products are licensed to you, not transferred. Reused building blocks, such as those in the SaaS product accelerator, stay under license while your custom code stays yours.
-
After delivery
Support and incident terms are agreed in an SLA when you request one.
Start a security conversation
Have a security questionnaire, a DPA template or a list of controls your auditors expect? Start a security conversation with Netbase and bring it along, with any certificate details your review needs. See what Netbase has delivered in our work, and the rest of the trust record under Why Netbase.
Discuss a project
Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.+84 937 869 689
91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam
Get in touch
Tell us what you want to build, modernize, or operate.