Security & data handling

See the boundary before you put data into the tool.

The Workbench separates browser-side file preparation, account-owned stored workspace data, simulator traffic and any future live Maximo connectivity.

Read technical details

Current public posture

  • Live customer Maximo requests disabled by default
  • Isolated guest workspaces
  • Optional one-time email resume links
  • Existing suspended accounts remain blocked
  • Viewer role is read-only

What happens to your data

Files are parsed in the browser

CSV, pasted spreadsheet data, JSON and XML are parsed in the client before a request is built.

Workspace data is account-scoped

Environments, saved load sets, runs, row results, audits and batches are retrieved through the signed-in account context.

Request views mask credentials

The request inspector shows the authentication header name with a masked value rather than returning configured secret material.

Simulator means no Maximo network call

Demo environments are handled by the Workbench simulator. A simulated result is labelled as simulated and is not evidence that a real tenant will accept the import.

Live targets are fail-closed

The Worker has explicit feature, host and secret checks before a live adapter can be allowed. The free web pilot does not rely on that path.

Private routes are not indexed

Authenticated application routes and API responses are served with no-index / no-store controls; the public marketing and guide pages remain readable.

Need a security review before using it?

Ask for the current architecture, data-flow and control summary and use the simulator with fictional data first.

Contact Assetize