Clear controls.
Clear responsibilities.
Security is a shared responsibility. Aiden uses Base44's platform capabilities, while access rules, source governance, integrations and review paths are configured for the agreed implementation.
What Base44 provides.
The statements below are based on Base44's published security documentation. They describe the platform foundation, not an unconditional guarantee for every Aiden configuration.
Encryption
Base44 states that platform data is encrypted at rest and in transit. Base44 also states that its data is not end-to-end encrypted.
Platform assurance
Base44 reports SOC 2 Type II and ISO 27001 certification. These are Base44 platform certifications, not separate certifications held by Aiden Solutions.
Access and data permissions
Base44 supports app roles plus row-level and field-level data permissions. The rules still need to be configured and reviewed for each use case.
Security scanning
Base44 provides scans for common app risks, vulnerable packages, exposed credentials and missing authentication checks.
Secrets and connectors
Credentials can be held in Base44's encrypted secret storage or managed connectors and used from backend functions instead of being exposed in browser code.
Plan-specific controls
Features such as enterprise SSO, audit logs and data-residency controls depend on the selected Base44 plan and the agreed implementation.
How enquiries are handled.
The public website is separate from authenticated administrative access. Its roadmap form sends the submitted fields—and limited campaign or referral context disclosed in the Privacy Policy—through server-side handling.
- Roadmap enquiries pass through a backend function that validates and sanitises submitted fields.
- Lead records are restricted to administrators through Base44 data permissions and are not readable from the public site.
- Interactive administrative pages and management actions are restricted to authenticated administrators.
- Connected-service credentials are accessed from backend functions rather than being embedded in the public website.
- The public Aiden demo uses labelled sample responses and does not accept or process customer documents.
Important Transparency
Security claims need scope.
Aiden Solutions does not claim that every possible deployment is automatically compliant with every regulatory framework, or that Base44's certifications become separate Aiden certifications.
Data residency, SSO, audit logging, integrations and other controls depend on Base44 plan availability and the implementation agreed with the customer.
Before using Aiden for sensitive or high-risk decisions, the customer and Aiden should agree the data boundary, permissions, source ownership, escalation rules and required legal or compliance review.
What we configure together.
Define the boundary
Agree which users, documents, workflows and decisions belong in the implementation—and which do not.
Configure access
Apply roles and data permissions to the agreed structure, then test the experience from each relevant user role.
Control the sources
Use approved content, define ownership and update processes, and make source references available where the use case requires them.
Route uncertainty
Identify higher-risk questions and define when the system should decline, signal uncertainty or hand the matter to a person.
Review before expansion
Run a focused pilot, inspect real usage and knowledge gaps, and review the security configuration before increasing scope.
Discuss your requirements before making assumptions.
Tell us what information, users and workflows you need to protect. We can use that context to scope an appropriate pilot and identify questions that need further technical, legal or compliance review.
Request a free AI roadmapFor privacy enquiries, email privacy@aiden.solutions.