Security model

Maester Cloud holds your security evidence, so its own security model is deliberately simple to audit.

Dedicated, isolated environments

Every hosted customer gets their own Azure resource group: their own portal, their own API, their own storage account, in the region they chose. There is no shared database and no multi-tenant application tier. Provisioning runs in a separate control plane under its own identity.

Identity: yours, not ours

  • Portal sign-in uses an Entra application registered in your tenant, created by you during setup. It holds no secret, no certificate, no Microsoft Graph permissions, and no app roles: it exposes one delegated scope, access_as_user, for the portal to call its API. A new user sees nothing until an Owner grants them a role, and you can also turn on Entra Assignment required so only people you assign can authenticate (assign the runner identity first). Your Conditional Access policies apply, because it's your app.
  • The API trusts only your tenant. Every portal request carries a token your tenant issued for your app; the API validates issuer, audience, signature, and tenant on each call. Report uploads are validated the same way: your environment rejects tokens from any other tenant.
  • Workloads use managed identities and workload identity federation wherever Microsoft supports it: report emails, for example, are sent by your deployment's own managed identity, scoped in Exchange to one shared mailbox, with no Mail.Send permission in Entra. The aim across the product is no secrets and no certificates, so there is nothing to store, rotate, or leak.

Data handling

  • What's stored: your raw report files and the parsed per-test results, in your region, in your environment's storage account.
  • Artifact access: report downloads stream through the authenticated API. We deliberately do not mint shareable storage URLs. A link that outlives the click is a bearer token, and we rejected that design.
  • Billing data stays with Polar (our merchant of record). Our systems keep only your Polar customer id, email, name, plan, and subscription status: no addresses, no payment details.
  • The portal page itself loads before sign-in (standard for single-page apps); it contains no data. Every piece of content requires a validated token from your tenant.

Things you control

  • Who can see what (roles on the portal's Access page), and optionally who can sign in at all (Assignment required in your Entra tenant).
  • Who can upload (token issuance in your tenant; the upload pipeline label tells you which pipeline sent each run).
  • The sign-in app itself: it requests no Microsoft Graph permissions, so there is no admin consent to grant. Setup permissions lists what each Maester Cloud app holds.