Baseten Security Practices
Last Updated: August 27, 2026
These Security Practices describe the administrative, physical, and technical safeguards Baseten maintains for Customer Content, and are incorporated into the Baseten Terms and Conditions available at https://www.baseten.co/terms, or other written agreement between Baseten Labs, Inc. and Customer referencing them (the "Agreement"). Capitalized terms used but not defined in these Security Practices have the meanings given in the Agreement.
BASETEN PLATFORM CONTROLS
Architecture and Data Segregation. Baseten operates a multi-tenant inference platform using shared infrastructure with logical separation of Customer Content. These measures include the use of access controls, unique customer identifiers, and namespace isolation to ensure that each customer's models, data, and workloads are segregated from those of other customers. For customers requiring additional isolation, Baseten offers single-tenant dedicated clusters and self-hosted deployment options within the customer's own VPC.
Multi-Cloud Infrastructure. Baseten utilizes multiple public cloud providers (including Amazon Web Services, Google Cloud Platform, and others) for its infrastructure. Baseten's multi-cloud capacity management architecture distributes workloads across cloud providers and multiple regions globally, enabling cross-provider redundancy, GPU failover, and region-locking for customers with data residency or compliance requirements.
Deployment Options. Baseten offers three deployment configurations to help meet varying security and compliance requirements:
Baseten Cloud: Fully managed, multi-cloud deployment with autoscaling across cloud providers and regions.
Self-Hosted: Full access to the Baseten inference stack within the customer's own cloud environment. No Customer Content leaves the customer's environment.
Hybrid: Combines self-hosted control with elastic spillover to Baseten Cloud for on-demand capacity. Customers define where workloads run.
Audits and Certifications. Baseten maintains an audit program designed to continuously monitor for vulnerabilities, non-compliance, and misconfigurations, performed by internal teams and accredited external firms. Baseten undergoes periodic SOC 2 Type II examinations conducted by an independent third-party auditor. Upon request and under a non-disclosure agreement, Baseten will make its most recent SOC 2 Type II report available to customers. Baseten's current certifications and attestations are available at https://trust.baseten.co/, and include:
SOC 2 Type II: Baseten has been independently audited under the AICPA Trust Services Criteria. The most recent SOC 2 Type II report is available to customers under NDA.
HIPAA: Baseten offers HIPAA-eligible deployment configurations and enters into Business Associate Agreements (BAAs) with qualifying customers. Baseten's infrastructure and controls are designed to support customers' HIPAA compliance obligations when a BAA is in effect.
GDPR: Baseten is committed to compliance with the General Data Protection Regulation and offers a Data Processing Addendum, available at https://www.baseten.co/dpa, to support customers' data protection obligations.
SECURITY CONTROLS
Baseten has established a comprehensive security control framework aligned to industry-leading practices. This framework is designed to safeguard the confidentiality, integrity, and availability of Customer Content that is processed, transmitted, or stored by Baseten.
Access Management. Baseten uses a centralized system for managing identities and governing access to all key systems. All access is granted based on approved requests following the principle of least privilege. Quarterly reviews of access to sensitive systems are conducted. Baseten enforces multi-factor authentication for all personnel.
Audit Logging. Baseten logs access and actions taken by Baseten personnel, as well as customer authentication-related events, including device type, IP addresses, and abnormality detection. Security-relevant logs are stored for up to 4 years, protected from unauthorized access, and cannot be deleted or modified, even by an administrator.
Host Management. Baseten enforces security requirements on all endpoints, including screen lockouts, full disk encryption, anti-malware and endpoint detection and response software, remote wiping and locking capabilities, and up-to-date software. Secure disposal of systems and media ensures that information is rendered undecipherable or unrecoverable prior to final disposal.
Network Protection. Baseten employs enterprise firewalls and layered architectures, intrusion detection systems, and network anomaly detection. Access to servers and databases in the production environment requires multi-factor authentication. Encrypted communications utilize Transport Layer Security 1.2+ (TLS 1.2+) at a minimum.
Cloud Security Posture Management. Baseten continuously monitors its cloud infrastructure across all Infrastructure Providers for misconfigurations, exposure, vulnerability, and patch management issues.
Application Security. Baseten has implemented a secure software development lifecycle. New features and significant changes undergo threat modeling and review. Continuous static and dynamic code scanning and software composition analysis are used to detect and mitigate vulnerabilities. Code changes are peer-reviewed prior to production deployment. Baseten engages qualified third-party security firms for periodic penetration testing.
Vulnerability Management. Baseten maintains a vulnerability assessment, patch management, and threat protection program. Vulnerabilities are tracked with assigned severities, owners, and remediation SLAs. Scheduled monitoring procedures identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
Change Management. All application code changes and material infrastructure changes go through Baseten's change management process, designed to track changes, ensure modifications are necessary and safe, and improve system functioning.
DATA ENCRYPTION
Encryption in Transit. All Customer Content is encrypted using cryptographically secure protocols (TLS v.1.2 or higher) in transit between the customer and the Services. Customer Content transferred between clusters is encrypted using mutually authenticated mTLS (TLS v.1.2 or higher).
Encryption at Rest. Customer Content within Baseten's control is encrypted at rest using AES-256 bit encryption (or the equivalent or better, depending on the applicable cloud service provider). Encryption keys are managed within the applicable cloud provider's key management service and are rotated periodically.
CUSTOMER CONTENT PROCESSING AND DATA RETENTION
Infrastructure-Only Processing. Baseten does not directly process Customer Content for its own purposes. Baseten's access to Customer Content is limited to providing an infrastructure layer for running customer inference workloads in secure, isolated containers. Baseten does not use Customer Content for model training, fine-tuning, or improvement of any algorithms.
Zero Data Retention Products. Baseten adheres to a Zero Data Retention ("ZDR") posture across all inference products. Product-specific details are set forth below.
Model APIs. Baseten's Model APIs product adheres to a Zero Data Retention posture for all Customer Content. Baseten will not store, retain, or otherwise make a persistent copy of model inputs or outputs during a customer's use of the Model APIs. "Zero Data Retention" means that Baseten shall not (a) log, record, or store Customer Content; or (b) save Customer Content to persistent storage (e.g., hard drives, solid-state drives, cloud storage, databases) after the real-time processing required for the provision of the Services.
Dedicated Inference. Baseten's Dedicated Inference product adheres to a Zero Data Retention posture for Customer Model inputs and outputs. Baseten will not store, retain, or otherwise make a persistent copy of Customer Model inputs or outputs during a customer's use of the Dedicated Inference product.
Asynchronous Inference. If Customer elects to enable asynchronous inference, model inputs get temporarily stored and queued for the duration of the request as described in the Documentation. These model input requests can stay in queue for up to 72 hours before being processed and then deleted. Asynchronous Inference does not store the Model Outputs.
Customer Model Weights. Customer Model weights are loaded dynamically into GPU memory and are not persisted to storage by default. Customers may enable weight caching via supported configurations; cached weights can be permanently deleted on request.
DATA RETENTION FOR OTHER PRODUCTS
Training. For thirty (30) days after the end of a customer's subscription term, Baseten will provide the customer access to the Services to allow retrieval of Customer Content. After such thirty (30) day period, Baseten will promptly delete all remaining Customer Content in its possession.
Dedicated Inference (non-input/output data). For thirty (30) days after the end of a customer's subscription term, Baseten will provide the customer access to the Services to allow retrieval of remaining Customer Content (such as Customer Models). After such thirty (30) day period, Baseten will promptly delete all remaining Customer Content in its possession.
Return and Deletion of Customer Content. During the term of a customer's subscription, the customer may export Customer Content via the Services, subject to the applicable services plan and configuration. Following the applicable post-termination retrieval period, Baseten will promptly delete all Customer Content in its possession. Residual copies of Customer Content may remain in backups for a limited period until they are overwritten or purged in accordance with Baseten's regular backup retention and lifecycle processes.
INCIDENT MANAGEMENT
Baseten has an established and documented incident response plan, reviewed at least annually and communicated to all relevant parties. Baseten has an incident response team that monitors incidents involving security, availability, processing integrity, and confidentiality. All incidents are documented in Baseten's security incident register, and all actions taken are documented and reviewed after resolution. Baseten notifies impacted customers without undue delay, and in any event within forty-eight (48) hours, of any unauthorized disclosure of their Customer Content of which Baseten becomes aware, to the extent permitted by law.
BUSINESS CONTINUITY AND DISASTER RECOVERY
Baseten has procedures designed to maintain service continuity and recover from foreseeable emergencies or disasters. Baseten's multi-cloud architecture provides inherent resilience through cross-cloud failover. Baseten performs regular backups of production systems, and backup recovery and deployment protocols are tested at least annually.
PERSONNEL PRACTICES
Baseten maintains personnel practices including hiring policies with background screening based on job function. Employees and contractors with access to Customer Content undergo background checks. All employees receive information security and privacy training during onboarding, with periodic training at least annually. Employees agree to Baseten's security policies and are bound by written confidentiality agreements.
Personnel are subject to: (i) role-based access limitations following least privilege; (ii) execution of confidentiality agreements; (iii) comprehensive privacy and security training; (iv) immediate termination of access upon conclusion of employment; (v) full audit logging of all access to backend infrastructure; and (vi) use of strong password complexity, and default multi-factor authentication.
INFRASTRUCTURE PROVIDERS AND SUBPROCESSORS
Baseten sources hardware, compute and networking resources through a combination of owned infrastructure and Infrastructure Providers (as defined in the Agreement), which include hyperscale cloud providers, specialized GPU cloud providers, hardware suppliers, and colocation facilities. Baseten may acquire, deploy, and operate the resources through any combination of ownership, lease, license, financing, or third-party service arrangements. Baseten also uses third-party Infrastructure Providers to provide compute, storage, and networking for the Services. Baseten also uses third-party entities ("Subprocessors") to process Customer Content on behalf of customers. A list of material Infrastructure Providers and Subprocessors is maintained at https://trust.baseten.co/.
Infrastructure Providers are not Subprocessors under Baseten's DPA, available at https://www.baseten.co/dpa, unless they have logical access to Customer Content containing personal data. Baseten carries out compliance reviews of its Subprocessors and imposes obligations on them to implement appropriate technical and organizational measures, in accordance with applicable data protection laws. Customers will be notified at least fifteen (15) days prior to engagement of any new Subprocessor, as described in Baseten's DPA.
Questions about these Security Practices? Contact security@baseten.co.