MaximaLabs
Security & Privacy

Security & data privacy

An honest account of how MaximaLabs handles your data — and where we're headed on compliance.

Current posture

  • Browser-based — no desktop agent or license server to install or patch.
  • Your data lives on a dedicated server (local Postgres + filesystem), reached only through the app and API.
  • Sessions use a signed, httpOnly cookie; API keys and secrets live in environment config, never in the repo or the client.
  • Real per-organization SAML 2.0 SSO (Okta, Azure AD, Ping) alongside Google SSO and email/password — an org admin configures their own IdP directly in the app, no support-assisted setup required.
  • Encryption in transit (HTTPS/WSS) to the server and to the one external dependency, the Anthropic API.
  • Nightly database dumps plus offsite object-storage backups; simulations are yours to export (CSV/PDF) at any time.
SOC 2 — on our roadmap

We're building toward SOC 2 Type II. We don't claim certifications we don't hold — if a formal security review is a prerequisite for your team, tell us where you are in procurement and we'll share our current controls and timeline.

Terms & contact

Full terms of service and a data-processing agreement are available on request. For security disclosures or compliance questions, contact contact@maximalabs.io.

Stop fighting legacy software. Build your first flowsheet in 60 seconds.