Skip to content

App Classifications

Airbase supports applications up to Confidential Cloud Eligible / Sensitive Normal (CCE/SN). Data classification should be understood as two separate dimensions: security classification and sensitivity level. These are assessed independently, not as a single linear scale.

In practice, this means an app deployed to Airbase should not handle data above the Confidential Cloud Eligible (CCE) security classification or above Sensitive Normal sensitivity. If your use case is within CCE/SN, Airbase is designed to support it; if your app handles higher-classified or more sensitive data, it should be deployed on a platform approved for that higher level instead.

For the official definitions of classification levels, refer to IM8 Data Classification. For a quicker matrix-style explainer, refer to the GovTech CDO Data Classification guidance.


Dimension 1: Security Classification

Security classification is determined by the potential damage to national interests if the data is disclosed. The levels are listed below in ascending order of classification.

Level Description
Official Open Information intended for public release, or where disclosure poses no risk to government operations or national interests.
Official Closed Information for internal government use. Not for public release, but disclosure does not endanger national security or operations.
Restricted Information whose unauthorised disclosure could cause harm to individuals, agencies, or government operations.
Confidential Cloud Eligible Confidential information approved for storage and processing on cloud infrastructure that meets specific security requirements.
Confidential Information whose unauthorised disclosure could cause serious harm to national security or government operations.
Secret Information whose unauthorised disclosure could cause grave harm to national security.
Top Secret Information whose unauthorised disclosure could cause exceptionally grave harm to national security.

Airbase supports up to Confidential Cloud Eligible (CCE)

Airbase is approved for applications classified up to Confidential Cloud Eligible (CCE). Applications at Confidential (non-CCE) and above must use platforms specifically accredited for those classification levels.


Dimension 2: Sensitivity

Sensitivity is a separate dimension that reflects the potential reputational, social, or economic harm caused by a data leak — typically involving personal data or information that could embarrass individuals or organisations.

Level Description
(Non-Sensitive) No significant reputational or personal harm expected if disclosed. This qualifier is often omitted when there is no sensitivity concern.
Sensitive Normal Disclosure could cause moderate reputational or personal harm. Applies to most personal data (e.g. name, NRIC, contact details, employment records).
Sensitive High Disclosure could cause serious reputational or personal harm. Applies to data such as medical records, financial details, criminal history, or information that could endanger individuals.

Airbase supports up to Sensitive Normal

Airbase supports applications handling data up to Sensitive Normal. Applications processing data classified as Sensitive High should consult the platform team before onboarding.


Supported Classifications on Airbase

Airbase supports the combinations of security classification and sensitivity listed below. Any combination exceeding Confidential Cloud Eligible Sensitive Normal is not supported.

Security Classification Non-Sensitive Sensitive Normal
Official Open
Official Closed
Restricted
Confidential Cloud Eligible
Confidential (non-CCE) and above

Assigning a Classification

When onboarding an application to Airbase, identify:

  1. The most sensitive data your application handles — this determines your sensitivity level.
  2. The potential harm of unauthorised disclosure — this determines your security classification.
  3. The combined label — e.g. Official Closed Sensitive Normal, or Restricted (Non-Sensitive).

If you are unsure of the correct classification, consult your agency's data protection officer or refer to your agency's IM8 implementation guide.

When in doubt, classify higher

It is safer to over-classify than to under-classify. You can request a reclassification downwards once the data scope is confirmed.


See Also