Encryption everywhere
TLS 1.2 or higher for all traffic. Data at rest, including artifacts, dataset snapshots and secrets, encrypted with AES-256. Enterprise customers can supply their own keys.
maclnote holds your training data, your model weights and the predictions your models make about real customers. Here is how the product protects them, and the choices you have about where they live.
TLS 1.2 or higher for all traffic. Data at rest, including artifacts, dataset snapshots and secrets, encrypted with AES-256. Enterprise customers can supply their own keys.
SAML and OIDC single sign-on with Okta, Microsoft Entra ID, Google Workspace and others. SCIM provisioning creates and removes users as your directory changes.
Permissions per workspace, project, dataset, model and endpoint. Data source access is inherited: a user who cannot read a table cannot read a snapshot of it.
Every read of data, run, registration, approval, deployment and permission change is recorded with actor, time and origin. Export to your SIEM on Enterprise.
Choose EU or US hosting on Team. Enterprise can run in any major cloud region, single-tenant, or entirely inside your own network with no data leaving it.
Run the full product on your own Kubernetes cluster with a Helm chart, or in your own cloud account with Terraform. Training, models and predictions never leave your network.
maclnote Cloud runs on major public cloud providers in isolated virtual networks. Each customer's notebooks, training jobs and prediction APIs run in dedicated containers; no two customers share a machine kernel. Data source credentials are stored in a managed vault, injected when a notebook or job starts, and never written to disk in plain text or shown in notebook output.
All code changes are peer reviewed and pass automated security scanning before release. Dependencies are monitored for published vulnerabilities and patched on a defined schedule, with critical issues addressed within days. Third-party penetration tests are performed regularly; the most recent summary is available under NDA.
The assistant reads your notebooks and training runs to answer questions and generate code. Your notebooks, training data, runs and models are never used to train models, ours or anyone else's. Enterprise customers can route assistant requests through their own model provider keys, or turn the assistant off entirely.
Data is replicated across availability zones and backed up daily with tested restores. Enterprise agreements include a 99.9% uptime SLA for the application and for deployed prediction APIs, with service credits. Prediction APIs keep answering requests while the application is being maintained.
Our controls are designed against recognised frameworks for security, availability and confidentiality, and we support customers' own GDPR, HIPAA and financial-services obligations through data processing agreements, residency options and retention controls. Detailed compliance documentation, including our most recent independent assessments, is available to prospective customers on request through the contact form.
If you believe you have found a security issue in maclnote, please report it through the contact form and select "Security" as the topic. We acknowledge reports promptly, keep you informed while we investigate, and credit researchers who wish to be named once an issue is resolved.