Security and privacy boundary
CryoMaestro is designed for institution-controlled deployment. Actual security and data residency depend on the configured identity system, network, storage, backups, integrations, extensions, remote access, and operator practice.
This overview is not a security certification or guarantee. Each organization must threat-model, test, monitor, and approve its own deployment.
Required controls
Section titled “Required controls”- Central identity, least-privilege roles, prompt deprovisioning, and protected administrator access
- Encrypted transport, segmented networks, restricted instrument paths, and controlled remote access
- Institution-owned storage permissions, backup protection, recovery tests, and documented retention
- Security logging with protected access, time synchronization, alerting, and reviewed retention
- Version and vulnerability management for the platform, integrations, operating environment, and extensions
- Incident response covering account compromise, data exposure, instrument behavior, and supply-chain risk
Validation
Section titled “Validation”Test both permitted and denied actions for every role. Review privileged, maintenance, extension, and break-glass paths separately. Confirm what leaves the environment by observing network and integration behavior rather than relying on a product description.
Customer-operated deployments need their own privacy, records-management, and research-data policies. The website Privacy Notice covers only this public website.