Budibase · Trust Center

Budibase Trust Center

Trust center

Budibase publishes a security page rather than a dedicated trust center — there is no trust.budibase.com (NXDOMAIN, probed 2026-09-04) and no document portal. The page states certifications, hosting geography, encryption posture and an audit cadence, but offers no downloadable evidence and no subprocessor list.

Budibase maintains a public trust center documenting ISO 27001, GDPR, and SOC 1 / SOC 2 compliance.

AI AgentsAutomationInternal ToolsLow-CodeOpen-SourceWorkflow-Automation
Trust center: https://budibase.com/security

Certifications & Compliance

ISO 27001GDPRSOC 1 / SOC 2

Source

Trust Center

Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: https://budibase.com/security
url: https://budibase.com/security
status: 200
verified: '2026-09-04'
description: >-
  Budibase publishes a security page rather than a dedicated trust center — there is no
  trust.budibase.com (NXDOMAIN, probed 2026-09-04) and no document portal. The page states
  certifications, hosting geography, encryption posture and an audit cadence, but offers no
  downloadable evidence and no subprocessor list.
certifications:
  - name: ISO 27001
    claimed: true
    scope: Budibase
    evidence: >-
      "ISO 27001 Certified" in the site footer; "ISO 27001 — Enterprise-grade security
      certifications to meet your compliance requirements" on the security page.
    report_available: false
  - name: GDPR
    claimed: true
    scope: Budibase
    evidence: '"GDPR Compliant" stated in the site footer.'
    report_available: false
  - name: SOC 1 / SOC 2
    claimed: false
    scope: infrastructure provider only
    evidence: >-
      The page says servers are "hosted within the EU (Ireland) in data centers certified
      by SOC 1/2 and ISO 27001". That certifies the DATA CENTRE, not Budibase. Budibase
      makes no SOC 2 claim of its own — recorded here so the inherited wording is not
      misread as a Budibase attestation.
    report_available: false
security_posture:
  hosting_region: EU (Ireland)
  data_in_transit: TLS 1.3, mandatory HTTPS
  data_at_rest: AES-256
  penetration_testing: >-
    "Annual penetration tests and AWS security configuration audits from 3rd party
    vendors."
  self_hosting: >-
    Open source, deployable via Kubernetes, Docker and more, including air-gapped
    deployments — the strongest data-sovereignty answer in this artifact.
platform_security_features:
  source: https://budibase.com/security and https://budibase.com/pricing.json
  features:
  - name: RBAC
    detail: Control the data and resources users can access. Also governs Public API key privileges.
  - name: SSO
    detail: Integrates with auth tools including OpenID Connect. Available on every plan.
  - name: Enforceable SSO
    detail: Business tier and above.
  - name: Audit logs
    detail: Comprehensive audit trails for user actions and system events. Enterprise tier only.
  - name: SCIM / Active Directory sync
    detail: Enterprise tier only.
  - name: Environment variables
    detail: Secure handling of database credentials and API keys across the platform.
  - name: User groups
    detail: Simplifies managing user access to apps.
gaps:
  - No dedicated trust portal; trust.budibase.com does not resolve.
  - No downloadable ISO 27001 certificate or audit summary, and no NDA-gated document room.
  - No published subprocessor list or data-processing addendum link on the security page.
  - No /.well-known/security.txt on any host — see security/budibase-vulnerability-disclosure.yml.
evidence:
  - source: https://budibase.com/security
    status: 200
    keywords:
      - iso 27001
      - gdpr
      - tls 1.3
      - aes256
      - penetration tests
      - air-gapped
  - source: https://trust.budibase.com
    status: 0
    result: DNS does not resolve (NXDOMAIN)
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/budibase-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.