Security

Security at Basefund

How we protect your account, your organization’s data, and the platform that moves it.

Signing in
No passwords.

Basefund has no passwords, so there is no password to steal, reuse or phish.

You sign in with a passkey (Face ID, Touch ID, Windows Hello or a security key), with a one-time code sent to your work email, or with your Google or Microsoft account. Every new account verifies both a work email address and a mobile phone before it is created.

Signing in

  • Sign-in codes are single use and expire after 15 minutes. Requesting a new one cancels the old one, and repeated wrong guesses are rejected.
  • Passkeys are bound to your device and to our domain, so a look-alike site cannot use them.
  • Whichever way you sign in, if it comes from a device we have not seen before, or from somewhere that does not fit your recent sign-ins, we also send a code to your mobile phone. You can then choose to trust that device, and we remember it for a year.
  • Every 90 days we re-confirm that your email address is still yours.
  • Sessions renew every 30 minutes, end after 8 hours without activity, and end after 18 hours regardless. The browser guide explains the cookies involved.
  • You can add or remove passkeys and trusted devices at any time in your profile.
Shared mailboxes cannot be used to sign in. Each person signs in with their own work email, so every action is attributed to a person; the shared mailboxes guide explains why.

Protecting your account

Most account takeovers start with a stolen or reused password. Basefund has neither.

  • One person, one account. Each email address belongs to exactly one account, and a sign-in identity can never be re-linked to someone else’s account.
  • Your email address cannot be changed from inside the app. A change goes through our support team, who verify the request with you and re-verify the new address before it takes effect.
  • Invitations and sign-up links are single use and work only for the person they were sent to.
  • We never ask for a sign-in code, and our email always comes from notifications@secure.basefund.com. The email guide shows how to recognize it.
  • Automated attacks are stopped at the edge: Cloudflare challenges bots before they reach us, and requests that look like scanning or probing are blocked and their source temporarily banned.
  • You can see every device you have trusted, and remove any you do not recognize, from your profile at any time.
  • Every sign-in is recorded with the method used and the device and network it came from, so our team can investigate anything unusual with you.

Verifying sensitive actions

Some actions are too important to rely on a sign-in that happened hours ago.

Before you add or approve a bank account, change your legal name, or change your mobile number, Basefund asks you to verify again, right then, with a passkey or a code. That verification is good for a short window and then lapses, so a laptop left open or a borrowed session cannot be used to redirect money or change who you are.

The same rule applies to our own staff. Any support action that touches your account, such as resetting your sign-in, changing your email address or recording an identity-verification decision, requires a fresh passkey verification from the staff member, and is logged.

Your organization stays in control

Your data belongs to your organization, not to any individual user, and your organization decides who can see and change it.

  • Your organization’s administrators decide who has access and what each person can do, and can change that at any time.
  • Access ends the moment someone is removed, and access can carry an end date that switches it off automatically, which suits contractors, auditors and seasonal staff.
  • An organization can never be left without an administrator, so control of its data never rests with a single person who might leave.
  • Every approval, edit and upload is attributed to the individual who made it, and a history of changes is kept.
  • Sharing a transaction with another firm gives that firm read access only; nobody outside your organization can change your records.
  • Basefund staff have no standing access to your workspace. When support needs to act inside it, they do so through an explicit, recorded access that is switched on for the task and off afterwards. Everything they do is recorded in an audit trail under their own name, and that record is kept after their access ends, so every action is attributed to a person, including our staff.

Your data

Encryption
Everything is encrypted in transit (TLS 1.2 or later) and at rest.
Bank account details
We keep only the last four digits and a fingerprint used to detect duplicates. Full account and routing numbers are held by our banking partner, and only the account’s owner can retrieve them.
Identity verification
Run by a specialist provider used across the banking industry. Basefund never stores your ID document or date of birth; we keep only the outcome.
Backups and recovery
The production database runs across multiple zones, is backed up continuously with 35 days of point-in-time recovery, and is mirrored to a second region for disaster recovery. Uploaded files are stored redundantly across multiple US regions.
Logs and error reports
Identity and financial fields are masked in our logs and error reports.
Service providers
We use a small number of specialist providers (authentication, identity verification, banking, email, SMS, support chat, error tracking) and share with each only what it needs.

Network and infrastructure

Basefund runs on Google Cloud behind Cloudflare, and nothing reaches our servers without passing through Cloudflare first.

Every request to app.basefund.com and api.basefund.com is inspected at Cloudflare’s edge before it reaches us: managed web application firewall rules screen for known attack patterns, bot detection challenges automated traffic, and requests from countries where we have no customers are turned away. Our servers accept connections only from Cloudflare’s own network. Anything that tries to reach them directly, bypassing those checks, is dropped at the network edge.

Inside our environment, services are isolated from one another by default. Each part of the platform can talk only to the parts it needs, and the application reaches the production database over a private, encrypted link inside our cloud network, never across the public internet. Every connection to the database must be encrypted.

Everything is encrypted in transit with TLS 1.2 or later, and browsers are told to use HTTPS only. Our infrastructure is defined in code and deployed through a reviewed change process, so production is never changed by hand, and every change is recorded.

Monitoring and response

We watch the platform around the clock, and the people who built it are the ones who respond.

  • Availability checks probe the application continuously from multiple locations, and current and historical availability is published at status.basefund.com.
  • Any privileged change to our cloud environment, such as a firewall rule, a network setting, an access permission or a database configuration, raises an alert to the engineering on-call channel the moment it happens, whether or not it was expected.
  • Application errors are captured and triaged as they occur, with identity and financial fields masked before anything is stored.
  • Network traffic logs are kept so that any unusual activity can be investigated after the fact.
  • Automated scanning checks our workloads for known vulnerabilities, and dependency updates are applied through the same reviewed change process as everything else.

Compliance and transparency

Our security program is monitored continuously against the SOC 2 framework, and our controls, policies and progress are published at trust.basefund.com.

Independent penetration testing is performed annually. We review our network boundary and access rules on a fixed annual cycle, apply security updates frequently through the same reviewed change process as everything else, and run automated compliance checks against our cloud accounts every day.

Questions from your security or IT team?

If your security or IT team has questions this page does not answer, write to us and we will get you to the right person.