Skip to content

Security and privacy boundary

CryoMaestro is designed for institution-controlled deployment. Actual security and data residency depend on the configured identity system, network, storage, backups, integrations, extensions, remote access, and operator practice.

No implied certification

This overview is not a security certification or guarantee. Each organization must threat-model, test, monitor, and approve its own deployment.

  • Central identity, least-privilege roles, prompt deprovisioning, and protected administrator access
  • Encrypted transport, segmented networks, restricted instrument paths, and controlled remote access
  • Institution-owned storage permissions, backup protection, recovery tests, and documented retention
  • Security logging with protected access, time synchronization, alerting, and reviewed retention
  • Version and vulnerability management for the platform, integrations, operating environment, and extensions
  • Incident response covering account compromise, data exposure, instrument behavior, and supply-chain risk

Test both permitted and denied actions for every role. Review privileged, maintenance, extension, and break-glass paths separately. Confirm what leaves the environment by observing network and integration behavior rather than relying on a product description.

Customer-operated deployments need their own privacy, records-management, and research-data policies. The website Privacy Notice covers only this public website.