Security at Basefund
How we protect your account, your organization’s data, and the platform that moves it.
Basefund has no passwords, so there is no password to steal, reuse or phish.
You sign in with a passkey (Face ID, Touch ID, Windows Hello or a security key), with a one-time code sent to your work email, or with your Google or Microsoft account. Every new account verifies both a work email address and a mobile phone before it is created.
Signing in
- Sign-in codes are single use and expire after 15 minutes. Requesting a new one cancels the old one, and repeated wrong guesses are rejected.
- Passkeys are bound to your device and to our domain, so a look-alike site cannot use them.
- Whichever way you sign in, if it comes from a device we have not seen before, or from somewhere that does not fit your recent sign-ins, we also send a code to your mobile phone. You can then choose to trust that device, and we remember it for a year.
- Every 90 days we re-confirm that your email address is still yours.
- Sessions renew every 30 minutes, end after 8 hours without activity, and end after 18 hours regardless. The browser guide explains the cookies involved.
- You can add or remove passkeys and trusted devices at any time in your profile.
Protecting your account
Most account takeovers start with a stolen or reused password. Basefund has neither.
- One person, one account. Each email address belongs to exactly one account, and a sign-in identity can never be re-linked to someone else’s account.
- Your email address cannot be changed from inside the app. A change goes through our support team, who verify the request with you and re-verify the new address before it takes effect.
- Invitations and sign-up links are single use and work only for the person they were sent to.
- We never ask for a sign-in code, and our email always comes from
notifications@secure.basefund.com. The email guide shows how to recognize it. - Automated attacks are stopped at the edge: Cloudflare challenges bots before they reach us, and requests that look like scanning or probing are blocked and their source temporarily banned.
- You can see every device you have trusted, and remove any you do not recognize, from your profile at any time.
- Every sign-in is recorded with the method used and the device and network it came from, so our team can investigate anything unusual with you.
Verifying sensitive actions
Some actions are too important to rely on a sign-in that happened hours ago.
Before you add or approve a bank account, change your legal name, or change your mobile number, Basefund asks you to verify again, right then, with a passkey or a code. That verification is good for a short window and then lapses, so a laptop left open or a borrowed session cannot be used to redirect money or change who you are.
Your organization stays in control
Your data belongs to your organization, not to any individual user, and your organization decides who can see and change it.
- Your organization’s administrators decide who has access and what each person can do, and can change that at any time.
- Access ends the moment someone is removed, and access can carry an end date that switches it off automatically, which suits contractors, auditors and seasonal staff.
- An organization can never be left without an administrator, so control of its data never rests with a single person who might leave.
- Every approval, edit and upload is attributed to the individual who made it, and a history of changes is kept.
- Sharing a transaction with another firm gives that firm read access only; nobody outside your organization can change your records.
- Basefund staff have no standing access to your workspace. When support needs to act inside it, they do so through an explicit, recorded access that is switched on for the task and off afterwards. Everything they do is recorded in an audit trail under their own name, and that record is kept after their access ends, so every action is attributed to a person, including our staff.
Your data
Network and infrastructure
Basefund runs on Google Cloud behind Cloudflare, and nothing reaches our servers without passing through Cloudflare first.
Every request to app.basefund.com and api.basefund.com is inspected at Cloudflare’s edge before it reaches us: managed web application firewall rules screen for known attack patterns, bot detection challenges automated traffic, and requests from countries where we have no customers are turned away. Our servers accept connections only from Cloudflare’s own network. Anything that tries to reach them directly, bypassing those checks, is dropped at the network edge.
Inside our environment, services are isolated from one another by default. Each part of the platform can talk only to the parts it needs, and the application reaches the production database over a private, encrypted link inside our cloud network, never across the public internet. Every connection to the database must be encrypted.
Everything is encrypted in transit with TLS 1.2 or later, and browsers are told to use HTTPS only. Our infrastructure is defined in code and deployed through a reviewed change process, so production is never changed by hand, and every change is recorded.
Monitoring and response
We watch the platform around the clock, and the people who built it are the ones who respond.
- Availability checks probe the application continuously from multiple locations, and current and historical availability is published at status.basefund.com.
- Any privileged change to our cloud environment, such as a firewall rule, a network setting, an access permission or a database configuration, raises an alert to the engineering on-call channel the moment it happens, whether or not it was expected.
- Application errors are captured and triaged as they occur, with identity and financial fields masked before anything is stored.
- Network traffic logs are kept so that any unusual activity can be investigated after the fact.
- Automated scanning checks our workloads for known vulnerabilities, and dependency updates are applied through the same reviewed change process as everything else.
Compliance and transparency
Our security program is monitored continuously against the SOC 2 framework, and our controls, policies and progress are published at trust.basefund.com.
Independent penetration testing is performed annually. We review our network boundary and access rules on a fixed annual cycle, apply security updates frequently through the same reviewed change process as everything else, and run automated compliance checks against our cloud accounts every day.
Related guides
Basefund in your browser
What your browser and network need to allow, how sessions and trusted devices work.
Email from Basefund
Where our email comes from, how it is authenticated, and how sign-in codes behave.
Shared mailbox sign-in
Why every person signs in as themselves, even when your firm works from a shared inbox.