Security

Built to be audited.

Needset handles the data that defines your models, so every decision it makes is attributable, reproducible and tamper-evident. This page describes the controls as implemented today. Detailed security documentation is available under NDA.

Identity and access

  • Passwordless sign-in: one-time email links (15 minutes, single use), sessions in HttpOnly cookies with CSRF protection
  • SSO via OpenID Connect with PKCE in the portal
  • Scoped API keys with roles: viewer, operator, approver, auditor, admin
  • Keys are shown once at creation and stored hashed
  • Per-key revocation without affecting other principals
  • Approvals require an authenticated principal; production deployments require SSO for approvals by default

Integrity

  • Deterministic plans: verification is recompilation and hash comparison
  • Optional HMAC plan signatures for offline verification
  • Every audit event is HMAC-chained to the previous one
  • Periodic signed audit anchors so an auditor can attest a range of the chain
  • Webhooks are HMAC-signed with a per-endpoint secret

Data handling

  • Originals stay in your object store; registration is read-only
  • Materializations stream through a spooled view and are not retained beyond the job
  • Tenant isolation at the catalog and key level
  • Customer bucket credentials are encrypted at rest with a key derived from the deployment secret and are never displayed after entry
  • Customer data is never used to train anything
  • Self-hosted deployment keeps every byte in your VPC

Application hardening

  • Strict Content-Security-Policy with a per-load nonce; no inline scripts without it
  • HSTS, nosniff, frame denial, referrer and permissions policies at the gateway
  • Path-safe upload handling; bundle extraction refuses traversal
  • Secrets read from files, never environment strings, in containers

Deployment

  • Containers run read-only with no-new-privileges
  • Backend network is internal; only the gateway is exposed
  • TLS terminated at the gateway with automatically renewed public certificates
  • Health and readiness endpoints for orchestration

Disclosure

Report a vulnerability to security@needset.ai. We acknowledge reports within two business days and will not pursue action against good-faith research that respects customer data.

Compliance. We are early. We do not currently hold third-party attestations and will not claim them until we do. What we can provide today is the control documentation above, architecture diagrams, and a self-hosted deployment so that your existing controls apply.

Need the detailed version?

Security documentation, architecture and the audit-chain specification are available to prospective customers under NDA.