Source
Security page — Basecamp
Checked for Basecamp on 28 Sep 2026
- Page
- https://basecamp.com/security
- Checked
- 28 Sep 2026, 03:00 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:76e1fae7ccba1318972926bff0144fcd7aa8323f2046888fcff47ff202642bea
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Backup and redundancy Report an error
“All data are written to multiple disks instantly, backed up daily, and stored in multiple locations.”
-
Transit encryption Report an error
“Whenever your data are in transit between you and us, everything is encrypted, and sent using HTTPS.”
-
At rest encryption Report an error
“Any files which you upload to us are stored and are encrypted at rest. Our application databases are generally not encrypted at rest — the information you add to the applications is active in our databases and subject to the same protection and monitoring as the rest of our systems. Our database backups are encrypted using GPG.”
-
Redundancy Report an error
“Our systems are engineered to stay up even if multiple servers fail.”
-
Physical security Report an error
“Our state-of-the-art servers are protected by biometric locks and round-the-clock interior and exterior surveillance monitoring. Only authorized personnel have access to the data center. 24/7/365 onsite staff provides additional protection against unauthorized entry and security breaches.”
-
Patching Report an error
“Our software infrastructure is updated regularly with the latest security patches. Our products run on a dedicated network which is locked down with firewalls and carefully monitored.”
-
Pci dss Report an error
“Card information is transmitted, stored, and processed securely on a PCI-Compliant network. Our current PCI DSS Certificate of Compliance (PDF), issued by SecurityMetrics on our SAQ A self-assessment, is renewed annually.”
-
Breach history Report an error
“To date, we’ve never had a data breach.”
-
Internal access audit Report an error
“We also audit internal data access. If a 37signals employee wrongly accesses customer data, they will face penalties ranging from termination to prosecution.”
-
Breach notification Report an error
“But in the unfortunate circumstances someone malicious does successfully mount an attack, we will immediately notify all affected customers.”
-
Caiq Report an error
“we publish our completed CSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.1, also available as a PDF. It answers all 283 questions of the Cloud Security Alliance’s Cloud Controls Matrix v4.1 as a self-assessment.”
-
Hecvat Report an error
“we publish our completed EDUCAUSE Higher Education Community Vendor Assessment Toolkit (HECVAT) 4, also available as a PDF, a CSV, and the filled official workbook.”
-
DPA contact Report an error
“Need a copy of our DPA or another questionnaire completed for your review? Email our Security team.”
-
Security response Report an error
“Have you noticed abuse, misuse, an exploit, or experienced an incident with your account? Please visit our Security Response page for details on how to securely submit a report.”
-
Hey security page Report an error
“For HEY, our email service, we have also a dedicated page. Go to hey.com/security to learn more.”
-
Company name Report an error
“If a 37signals employee wrongly accesses customer data”
Scores citing this record
- The Bootstrapper European sovereignty
- The Bootstrapper European sovereignty
- The Bootstrapper European sovereignty
- The Bootstrapper European sovereignty
- The Bootstrapper European sovereignty
- The Data Protection Officer European sovereignty
- The Data Protection Officer European sovereignty
- The Data Protection Officer Support & documentation
- The Data Protection Officer European sovereignty
- The Data Protection Officer European sovereignty
- The Data Protection Officer European sovereignty
- The Enterprise Architect European sovereignty
- The Enterprise Architect European sovereignty
- The Enterprise Architect European sovereignty
- The Enterprise Architect European sovereignty
- The Enterprise Architect European sovereignty
- The Integrator European sovereignty
- The Integrator European sovereignty
- The Integrator European sovereignty
- The Integrator European sovereignty
- The Integrator European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic Support & documentation
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The UX Purist European sovereignty
- The UX Purist European sovereignty
- The UX Purist European sovereignty
- The UX Purist European sovereignty
- The UX Purist European sovereignty
- The UX Purist European sovereignty