Security
Built to be audited.
Needset handles the data that defines your models, so every decision it makes is attributable, reproducible and tamper-evident. This page describes the controls as implemented today. Detailed security documentation is available under NDA.
Identity and access
- Passwordless sign-in: one-time email links (15 minutes, single use), sessions in HttpOnly cookies with CSRF protection
- SSO via OpenID Connect with PKCE in the portal
- Scoped API keys with roles: viewer, operator, approver, auditor, admin
- Keys are shown once at creation and stored hashed
- Per-key revocation without affecting other principals
- Approvals require an authenticated principal; production deployments require SSO for approvals by default
Integrity
- Deterministic plans: verification is recompilation and hash comparison
- Optional HMAC plan signatures for offline verification
- Every audit event is HMAC-chained to the previous one
- Periodic signed audit anchors so an auditor can attest a range of the chain
- Webhooks are HMAC-signed with a per-endpoint secret
Data handling
- Originals stay in your object store; registration is read-only
- Materializations stream through a spooled view and are not retained beyond the job
- Tenant isolation at the catalog and key level
- Customer bucket credentials are encrypted at rest with a key derived from the deployment secret and are never displayed after entry
- Customer data is never used to train anything
- Self-hosted deployment keeps every byte in your VPC
Application hardening
- Strict Content-Security-Policy with a per-load nonce; no inline scripts without it
- HSTS, nosniff, frame denial, referrer and permissions policies at the gateway
- Path-safe upload handling; bundle extraction refuses traversal
- Secrets read from files, never environment strings, in containers
Deployment
- Containers run read-only with no-new-privileges
- Backend network is internal; only the gateway is exposed
- TLS terminated at the gateway with automatically renewed public certificates
- Health and readiness endpoints for orchestration
Disclosure
Report a vulnerability to security@needset.ai. We acknowledge reports within two business days and will not pursue action against good-faith research that respects customer data.
Compliance. We are early. We do not currently hold third-party attestations and will not claim them until we do. What we can provide today is the control documentation above, architecture diagrams, and a self-hosted deployment so that your existing controls apply.
Need the detailed version?
Security documentation, architecture and the audit-chain specification are available to prospective customers under NDA.