Base44 holds SOC 2 Type II and ISO 27001 certification, publishes a data processing addendum for GDPR, and does not claim HIPAA compliance or offer a business associate agreement. Those four verdicts were checked against Base44’s own documentation on 29 July 2026. Not one of them describes the app you built on it.

A founder who reads “SOC 2 Type II” on a trust center and decides the compliance question is handled has made a reasonable call about a real certificate. The certificate is genuine. What it attests to is Base44’s internal controls, and the question a regulator, an enterprise customer, or a hospital procurement team puts to you is about your app. I audit that second layer for a living, and the space between the two is where every compliance surprise I have found actually sat. Whether Base44 is safe splits the same way, platform on one side and your build on the other.

Base44 compliance in 2026: the four verdicts, with sources

RegimeBase44’s own postureWhat your app still owesSource, verified 29 July 2026
SOC 2 Type IICertified. “Base44 is compliant with SOC 2 Type II.” The full report is shared only under an NDA, requested through the trust center.Every authorization check inside your app. The report covers Base44’s controls, never yours.Base44 docs · trust center
ISO 27001Certified. “Base44 is ISO 27001 certified”, covering “international standards for managing information security and privacy controls.”The same. An information-security management certificate describes how Base44 is run, not what your app returns to a stranger.Same two pages
GDPRNo such thing as GDPR certified. Base44 publishes a public DPA and states it “shall be considered your processor, and in no event shall be considered as the controller of the data.”Controller duties: lawful basis, consent, data export, deletion that actually cascades, 72-hour breach notification.base44.com/dpa
HIPAANot claimed anywhere. No public BAA. The Terms allow protected health information only “if expressly agreed by the Company in prior writing.”Everything a covered entity owes. Without a BAA there is no compliant path for PHI.Terms of Service, updated 22 June 2026

What Base44’s SOC 2 Type II and ISO 27001 certifications actually attest to

Base44’s certification doesn’t extend to the applications customers build on the platform. An auditor examined how Base44 manages access, incidents, and infrastructure over a period of time. That auditor never opened your entities, never logged in as one of your customers, and never checked a single permission level you set.

Base44 draws that boundary itself. Its trust center describes the certifications as evaluating “the design and effectiveness of security and operational controls”, then separately lists the security features it hands you, including row-level security and access control. The second list is a set of tools you still have to point at the right entities.

What the certification covers
What it doesn't cover for your app
How Base44 manages access to its own infrastructure, its incident response, its change management, audited independently over time
Whether the entity holding your customers’ records is set to Creator Only or left on All Users
Internal and third-party penetration testing of Base44’s environment, run against OWASP methodologies
Whether a stranger can read another customer’s row through your app’s own API, which no test of Base44’s environment would reach
A vendor-security answer good enough for most procurement questionnaires about the platform itself
The answer to "who can see this data", which is the question the same questionnaire asks about your product
What the certification covers
How Base44 manages access to its own infrastructure, its incident response, its change management, audited independently over time
Internal and third-party penetration testing of Base44’s environment, run against OWASP methodologies
A vendor-security answer good enough for most procurement questionnaires about the platform itself
What it doesn't cover for your app
How Base44 manages access to its own infrastructure, its incident response, its change management, audited independently over time
Whether the entity holding your customers’ records is set to Creator Only or left on All Users
Internal and third-party penetration testing of Base44’s environment, run against OWASP methodologies
Whether a stranger can read another customer’s row through your app’s own API, which no test of Base44’s environment would reach
A vendor-security answer good enough for most procurement questionnaires about the platform itself
The answer to "who can see this data", which is the question the same questionnaire asks about your product

A SOC 2 report says an auditor checked how Base44 runs its own systems. Nobody audited whether your app checks who owns the row it just returned.

Is Base44 HIPAA compliant in 2026, and will it sign a BAA?

Base44 is not HIPAA compliant and does not offer a business associate agreement. The word HIPAA doesn’t appear on Base44’s trust center, its privacy and security documentation, or its Terms of Service, and no BAA is publicly available. Three independent reviews reached the same conclusion within six weeks of each other in spring 2026.

Under HIPAA, a vendor that creates, receives, maintains, or transmits protected health information on your behalf has to sign a BAA before any of that is lawful, and no volume of SOC 2 evidence substitutes for that one signature. Platforms that will sign one publish the terms: Supabase is HIPAA compliant on its Team plan with a BAA and a paid add-on, which is the shape of the thing Base44 does not offer. HIPAA Vault put it plainly on 6 March 2026: “there is no publicly documented evidence that Base44 advertises HIPAA compliance or provides a standard HIPAA Business Associate Agreement (BAA).” Specode reached the same answer on 24 March, and Paubox on 9 April: “Base44 does not publicly offer a BAA in the legal and support materials reviewed.” All three are vendor pages that end in a pitch to migrate, so read them for the verdict rather than the recommendation.

Base44’s own Terms are the part nobody else quotes in full. Section 4.3 requires that “no sensitive data that is protected under special legislation and requires unique treatment (such as protected health information or credit, debit or other payment card data) will be shared with the Platform, other than if expressly agreed by the Company in prior writing and the appropriate agreement is in place.” That’s a conditional restriction rather than a flat ban, and the condition is a written agreement most builders have never thought to ask for.

Meanwhile Base44 runs a marketing page headed “Build your own medical records app with AI”, promising “a fully functional medical records app in minutes” that “tracks medical history, schedules appointments, and provides reminders for follow-up care.” That page mentions no compliance regime at all. The platform sells the use case, and the contract puts the regulated version of it behind a door you have to knock on first. De-identification is the usual way around that, and it is a higher bar than deleting names: a record still re-linkable through dates, a rare condition, or a postcode has not been de-identified.

Is a Base44 app GDPR compliant by default, or is that your job?

A Base44 app isn’t GDPR compliant by default, because GDPR compliance isn’t something a platform can hand you. Base44’s DPA is explicit that it acts as your processor and “in no event shall be considered as the controller of the data.” Controller is you, and that one word carries most of what follows.

What a processor owes, Base44 covers: security measures, sub-processor management, transfer mechanisms including standard contractual clauses. What a controller owes stays with you, and it’s the longer list. A lawful basis for each thing you collect. A consent record you could produce eighteen months later. A working data export. A deletion that reaches every table, including the audit rows, the analytics copy, and the file storage, rather than flipping a deleted boolean and leaving the row where it was. A 72-hour breach notification path that exists before you need it. Base44 publishes compliance@base44.com for data-export requests aimed at its own layer; a request about the records inside your app lands on you.

Deletion is the one that breaks most often in AI-built apps, for a boring reason: the delete button was written against the table the feature lived in, and every table added afterwards keeps its copy. What an export has to contain, and how long you’re allowed to keep any of it, are their own subjects.

Where does Base44 store your app’s data, and can you keep it in the EU or UK?

Base44 stores app data in the United States by default, with EU or UK storage only on the Elite and Enterprise plans. The docs say it outright: “All Base44 servers are currently located in the United States. By default, data for all workspaces is stored in the US.”

Base44 calls this data residency, and the option carries four limits, any one of which can undo the reason you went looking for it. Base44’s docs state that “as of April 16, 2026, if you have the Elite or Enterprise plan, you can choose to store your app data in EU or UK clusters instead of the default US region”, and add that the setting “applies to apps created after that date; it does not affect apps created before.” The feature is “rolling out gradually and may not be available in your workspace yet.” Then the sentence a data protection officer will circle: “Data residency controls where your data is stored, not where it is processed.” Media files, account details, and billing information stay in the US regardless of the setting.

The subprocessor list is where an app’s data actually travels, and Base44 publishes it. Mongo, SendGrid, Render, Google Cloud, OpenAI, Anthropic, and Datadog are listed in the US. Langfuse, handling LLM logging, is in Germany. Logfire, handling general logging, is in the UK. Wix.com Ltd. is in Israel, listed as a subprocessor for “providing and improving the services.” If your app has an AI feature, two of those rows are about you: whatever a user types into a prompt reaches an LLM provider, and a log of that call lands with a logging vendor in another country. Your privacy policy has to name both.

What a certified platform does not cover: what the audits actually found

Across the 21 third-party apps in the AxonBuild corpus, audited in June and July 2026, at least 5 exposed personal or health data outright, and 7 let a logged-in user read or write another customer’s records. No Base44 app has been through the audit yet. None of that is a Base44 rate and I’m not going to present it as one, which is the same line the wider question of whether Base44 is safe holds. What transfers is the mechanism, and it is the part of Base44 data security that no certificate reaches. Nothing in the price list reaches it either, which is why what Base44 integration credits cost at runtime ends at the same boundary from the billing side.

The clearest case in the corpus was an incident-timeline tool that marketed GDPR and HIPAA workflows. Its exported reports stamped “encrypted at rest” and “access logged” onto the output. Neither control existed. The app had no authentication at all, its AI-generated compliance verdict could be steered by text a visitor typed into the incident field, and it scored 57 out of 100. Nobody set out to lie. Someone asked an AI builder for a compliance report template, got one, and the template’s reassuring footer became a claim the moment a customer read it.

A second app failed the same way one layer down, and it is the one I would put in front of any founder who thinks a written control counts as a control. A multi-tenant health-data platform, sold as AI guardrails for clinical records, did write a HIPAA audit trail. The trail was written after the clinical record had already committed, in a step that swallowed its own errors, so a change could persist with no immutable record of it and still return success to the caller. The audit log existed, and on the days it would have mattered it was incomplete, with nothing in the app to say so. That’s why AI coding tools ship security holes by default applied to a compliance control. The same split runs through whether Lovable is safe and whether Supabase is safe, on platforms whose certificates are just as real.

A 10-minute compliance self-check on the Base44 app you already have

Six passes over your own app, none of which Base44 can run for you. Set aside ten minutes and a spare login.

  1. 01 Open every entity holding anything personal and read its permission level for all four operations. Creator Only or narrower, or you have a reason written down for why not.
  2. 02 Log in as a second account and try to reach a record belonging to the first, through an edited URL or ID. A result coming back is a cross-customer read, whether or not anything warned you at publish time.
  3. 03 Delete a test account, then go looking for its rows in every other entity: activity logs, uploaded files, anything analytics touched. Whatever survives is what a deletion request will not reach.
  4. 04 Try to export everything one account holds. If no route exists, a GDPR access request currently has no answer.
  5. 05 Force an error on a path that touches personal data and read what the log recorded. An error handler that dumps the whole request object writes that data somewhere new.
  6. 06 Read your own privacy policy against Base44’s subprocessor list and check that every LLM and logging vendor your app reaches is actually named in it.

If your app carries health data, payment data, or EU personal data, the next step after that list is to have someone check the data paths against what you’re claiming, because the claim is what creates the liability. Everything else here is a platform fact you can verify in an afternoon. That one sits in your own code, alongside the rest of whether your app is ready to launch.

Common questions about Base44 and compliance

Does Base44’s SOC 2 Type II certification cover the app I built on it?

No. The report covers Base44’s own infrastructure and operational controls, audited independently over a period of time, and no auditor examined your entities, your permission levels, or whether a signed-in stranger can reach another customer’s records through your API. Share Base44’s certification as evidence about your vendor. It is not evidence about your product.

Does Base44’s EU data residency option apply to an app I already built?

No. Base44’s documentation states that the EU and UK storage setting “applies to apps created after that date”, meaning 16 April 2026, and “does not affect apps created before.” An app built before then stays on US storage whatever plan you move to, so an EU residency requirement discovered late is a rebuild rather than a settings change. The option is limited to Elite and Enterprise plans and was still rolling out gradually as of July 2026.

What did Wix’s acquisition of Base44 change for compliance?

It changed who you contract with, and little else. The Terms of Service now open by naming “Wix.com Ltd., which operates the Base44-branded services” as the contracting company, while the DPA still names Base44, Inc. and the subprocessor directory lists Wix.com Ltd. (Israel) as a vendor row. The certification chain did not follow: Base44 runs its own trust center, its own privacy policy, and its own SOC 2 and ISO 27001 certificates, and nothing Wix publishes claims to cover apps built on Base44. Answer a due-diligence questionnaire with Base44’s posture, not Wix’s.

Can I build a healthcare app on Base44?

You can build one. Whether you can put real patient data in it is a different question, and today the answer is no without a written agreement Base44 hasn’t made publicly available. A prototype on synthetic data is fine. The moment a real patient record enters it, you’re holding an obligation nobody signed for.