Security
Security boundaries and vulnerability reporting for the Ubi Biologics product.
Product security boundary
Projects, datasets, uploads, jobs, results, and private model workspaces require an authenticated account. Authorization is enforced by the product API, PostgreSQL roles, and row-level security; public browser credentials are not privileged service credentials.
Scientific execution
Released scientific operations execute on private Ubi-managed workers. Normal browsers and the public product MCP do not call tool containers directly. A release entry is not sufficient without operation readiness and runtime admission.
Verified claim boundary
Production ingress uses HTTPS, server-held provider credentials, scoped transfer credentials, private scientific workers, and immutable provenance. This public page does not claim a security certification, penetration-test cadence, DPA, BAA, or service level that has not been separately verified.
Report a vulnerability
Use the published security contact for suspected vulnerabilities. Do not include sensitive customer or patient data in an initial report.
Last updated: 1 August 2026.