Security & Privacy
Security & data privacy
An honest account of how MaximaLabs handles your data — and where we're headed on compliance.
Current posture
- ✓Browser-based — no desktop agent or license server to install or patch.
- ✓Your data lives on a dedicated server (local Postgres + filesystem), reached only through the app and API.
- ✓Sessions use a signed, httpOnly cookie; API keys and secrets live in environment config, never in the repo or the client.
- ✓Real per-organization SAML 2.0 SSO (Okta, Azure AD, Ping) alongside Google SSO and email/password — an org admin configures their own IdP directly in the app, no support-assisted setup required.
- ✓Encryption in transit (HTTPS/WSS) to the server and to the one external dependency, the Anthropic API.
- ✓Nightly database dumps plus offsite object-storage backups; simulations are yours to export (CSV/PDF) at any time.
SOC 2 — on our roadmap
We're building toward SOC 2 Type II. We don't claim certifications we don't hold — if a formal security review is a prerequisite for your team, tell us where you are in procurement and we'll share our current controls and timeline.
Terms & contact
Full terms of service and a data-processing agreement are available on request. For security disclosures or compliance questions, contact contact@maximalabs.io.