Repository navigation
docs: remove AI-sounding style (em dashes, emojis, marketing tone, bare URLs) #502
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from 1 commit
14ba547
d4c568c
72fcd81
b105d8f
7e4db15
ce950b2
67d9f04
bb21990
9d654fb
4289585
6777d72
0927316
5e44c93
d668ebc
2109607
8b385ff
d16a70d
dd710e3
9c22101
19943d8
b2e93a9
ef1f328
d211e00
7418c3a
4a605d4
6fb46ad
4c7b860
d717120
6c59f54
13a8f94
1b0438d
bd99308
fe4d340
c827a4a
f570616
19ee4da
12eefa8
6270c27
521d453
9400ae7
d23935d
362c120
ba15545
ba13ea9
3221170
e828466
63618a9
e5fdfff
ed0aaeb
674ce3b
35076b8
a1eef8f
ca29df1
5ac3a64
7b3b8a9
26fa90f
6ad745f
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
Signed-off-by: Srihari Thyagarajan <hari.leo03@gmail.com>
- Loading branch information
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,60 +5,58 @@ noIndex: false | |
| noContent: false | ||
| --- | ||
|
|
||
| Deepnote is built on industry-leading security and privacy standards that keep our customer's data secure while connecting, querying, analyzing, and sharing. It offers a secure environment for teams to connect, analyze, and share data without compromising on data protection standards. | ||
| Deepnote uses security and privacy controls to protect customer data while teams connect, query, analyze, and share it. | ||
|
|
||
| As evidence of this, we've earned our SOC 2 Type II certification — a rigorous, third-party validation that our security practices and processes are built to meet the highest standards. | ||
| Deepnote has earned SOC 2 Type II certification, which provides third-party validation of its security practices and processes. | ||
|
|
||
| Visit [https://deepnote.com/security](https://deepnote.com/security) for more detail on Deepnote's Security and Compliance posture. | ||
| Visit the [Deepnote Trust Center](https://deepnote.com/security) for details about security and compliance. | ||
|
|
||
| ### Data security is core to how we work | ||
| ## Data security is core to how we work | ||
|
|
||
| At Deepnote, security isn't just a feature — it's foundational to how we build and operate. From day one, every team member is trained on security best practices, with clear accountability for protecting customer data and privacy. We embed security deep into our workflows, aligning with the standards required for SOC 2 compliance. | ||
| Deepnote trains each team member on security practices and makes them accountable for protecting customer data and privacy. Our workflows follow the standards required for SOC 2 compliance. | ||
|
|
||
| We invest heavily in proactive defenses, including regular third-party penetration testing and a [private bug bounty program](https://deepnote.com/.well-known/security.txt), to stay ahead of emerging threats. Security is everyone's job at Deepnote — and we take it seriously. | ||
| Deepnote commissions third-party penetration tests and runs a [private bug bounty program](https://deepnote.com/.well-known/security.txt). | ||
|
|
||
| ### Analyze without extracting | ||
| ## Analyze without extracting | ||
|
|
||
| Deepnote powers your work through live queries directly against your data sources — no unnecessary extraction, duplication, or downloads to local machines. Forget about scattered .csv files, outdated Excel exports, or risky third-party storage. With Deepnote, data stays exactly where it belongs: securely in your warehouse, accessed only when needed. | ||
| Deepnote queries your data sources live. You don't need to extract or duplicate data or download it to a local machine. The source data stays in your warehouse until a query needs it. | ||
|
|
||
| Inside projects, data is ephemeral by design — living just long enough in memory to power your analysis, then disappearing. [Our configurable caching](/docs/sql-query-caching) lets you fine-tune query costs without forcing long-term data storage or security trade-offs. Minimal movement, maximum control. | ||
| Projects keep data in memory while an analysis runs. [Configurable caching](/docs/sql-query-caching) lets you control query costs and how long Deepnote stores query results. | ||
|
|
||
| ### Architecture | ||
| ## Architecture | ||
|
|
||
| Deepnote's workspace is architected from day one with security at the core. Database credentials are encrypted at rest and stored securely in a vault, never exposed in plain text. When you run a query, Deepnote connects live to your data source, returns results into an isolated execution environment, and optionally caches results — always under your control. | ||
| Deepnote encrypts database credentials at rest and stores them in a vault instead of exposing them as plain text. When you run a query, Deepnote connects to the data source and returns the results to an isolated execution environment. Deepnote caches results when you enable caching. | ||
|
|
||
| Workspace admins have full control over access policies — managing who can connect to databases, who can view or edit projects, and how data is shared across teams. Fine-grained permissions meet enterprise-grade security, without adding friction to your workflow. | ||
| Workspace admins manage who can connect to databases, view or edit projects, and share data across teams. | ||
|
|
||
| ### Product access controls | ||
| ## Product access controls | ||
|
|
||
| Deepnote supports secure authentication out of the box, with [full SSO integrations](/docs/sso) for Google Workspace, Okta, and any OIDC-compliant provider. | ||
| Deepnote supports [single sign-on integrations](/docs/sso) for Google Workspace, Okta, and any provider that supports OpenID Connect (OIDC). | ||
|
|
||
| Our access model is built to meet the needs of teams handling sensitive data — whether for GDPR compliance, sector-specific regulations, or internal security policies. Deepnote's flexible controls give you precision over who can see, query, and collaborate on your projects. | ||
| Teams can use access controls to meet General Data Protection Regulation (GDPR) requirements, sector-specific regulations, or internal security policies. These controls determine who can see, query, and collaborate on projects. | ||
|
|
||
| Access management in Deepnote breaks down into three key layers: | ||
|
|
||
| - **User Roles**: Define what actions users can take inside Deepnote — from editing notebooks to managing workspace settings — with smart defaults and customizable role assignment. | ||
| - **Data Access**: Control who can connect to which databases. Limit users to pre-approved connections or credentials, minimizing risk and exposure. | ||
| - **Project Access**: Fine-tune who can view, edit, or publish projects and apps, putting full control over logic, outputs, and shared insights into the right hands. | ||
| - **User roles:** Define which actions users can take, from editing notebooks to managing workspace settings. | ||
| - **Data access:** Control which databases each user can connect to. You can limit users to pre-approved connections or credentials. | ||
| - **Project access:** Control who can view, edit, or publish projects and apps. | ||
|
|
||
| Security isn't an afterthought at Deepnote — it's baked into every layer of the product. | ||
| ## Deployment options | ||
|
|
||
| ### Deployment options | ||
| Deepnote offers multi-tenant cloud hosting and dedicated single-tenant deployments. Contact [sales@deepnote.com](mailto:sales@deepnote.com) to discuss region-specific data residency or deployment in a virtual private cloud (VPC). | ||
|
|
||
| Deepnote offers flexible deployment models to meet your team's needs — from secure multi-tenant cloud hosting to dedicated single-tenant deployments for organizations with stricter compliance or privacy requirements. For specialized hosting (like region-specific data residency or private VPC deployment), reach out to us directly at [sales@deepnote.com](mailto:sales@deepnote.com) — we'll tailor the best setup for you. | ||
| ## What data does Deepnote store? | ||
|
|
||
| ### What data does Deepnote store? | ||
| Deepnote uses Amazon Web Services (AWS) for processing and storage. Deepnote encrypts database credentials, file uploads, and cached query results at rest with 256-bit Advanced Encryption Standard (AES) encryption. Transport Layer Security (TLS) 1.2 or higher protects data in transit between Deepnote's servers and your browser. | ||
|
|
||
| Deepnote leverages AWS for processing and storage, with security baked in at every layer. Data at rest — including database credentials, file uploads, and cached query results — is encrypted using AES 256-bit encryption. Data in transit is protected with TLS 1.2 or higher, securing network traffic between Deepnote's servers and your browser. Your data stays safe, wherever it moves. | ||
| Other compute providers may store an encrypted temporary copy of workspace data. Deepnote uses AWS for long-term data storage. | ||
|
|
||
| Additionally, an encrypted temporary copy of users' workspace data can be stored on other compute providers' machines. AWS is used for long-term data storage. | ||
| ## Does Deepnote use customer data to train, fine-tune, or otherwise improve any AI/ML models? | ||
|
|
||
| ### Does Deepnote use customer data to train, fine-tune, or otherwise improve any AI/ML models? | ||
| No. Deepnote does not use customer data to train, fine-tune, or improve AI or machine learning models. Deepnote connects to external AI services such as OpenAI and Anthropic through secured APIs under enterprise agreements that prohibit training on customer data. Deepnote does not send personal, sensitive, or project data to model providers by default. Anthropic has a zero-data retention agreement, while OpenAI retains data for 30 days under its agreement. | ||
|
|
||
| No, Deepnote does not use customer data to train, fine-tune, or otherwise improve any AI or ML models. Deepnote integrates external AI services (such as OpenAI and Anthropic) via secured APIs under enterprise agreements that explicitly prohibit training on customer data. No personal, sensitive, or project data is sent to model providers by default, and zero-data retention agreements are in place for Anthropic (30-day retention for OpenAI under strict protections). | ||
| Deepnote does not host or fine-tune models. Deepnote encrypts customer data with AES-256, stores it in the customer's AWS environment, and applies its SOC 2 Type II-certified security practices. Customers choose whether to use the AI features. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- repository guidance ---'
for f in /tmp/coderabbit-repo-knowledge/deepnote-deepnote-4f22e1a3/*/*.md; do
printf '\n--- %s ---\n' "$f"
head -80 "$f"
done
printf '%s\n' '--- target file ---'
cat -n docs/security-overview.md | sed -n '40,65p'Repository: deepnote/deepnote Length of output: 13586 Resolve the AWS storage-location claim. Line 58 says customer data is stored in the customer’s AWS environment. Lines 50 and 52 state that Deepnote uses AWS for processing and long-term storage. Qualify the statement by deployment type or replace it with the correct storage location. 🤖 Prompt for AI Agents |
||
|
|
||
| Deepnote itself does not host or fine-tune any models internally, and all customer data remains encrypted (AES-256), stored within the customer's AWS environment, and protected under SOC 2 Type II-certified security practices with full user control. AI features are assistive only, optional, and fully transparent, ensuring that customer data privacy, GDPR compliance, and security standards are upheld at all times. | ||
| ## Support | ||
|
|
||
| ### Support | ||
|
|
||
| For all customers, Deepnote provides technical support via Intercom and email weekdays from 9 am to 5 pm Pacific Time as a minimum. Support via Slack channel may also be provided upon request. | ||
| Deepnote provides technical support through Intercom and email on weekdays from 9 a.m.-5 p.m. PT. Customers can also request support through a Slack channel. | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: deepnote/deepnote
Length of output: 10928
🏁 Script executed:
Repository: deepnote/deepnote
Length of output: 5959
🌐 Web query:
Anthropic zero data retention agreement applies products approved enterprise API use exceptions official💡 Result:
Anthropic's Zero Data Retention (ZDR) is a contractual arrangement that prevents Anthropic from storing customer prompts or model responses at rest after an API response is returned, except as required to comply with law or combat misuse and harm (e.g., enforcing Usage Policies) [1][2][3]. ZDR is not a default setting and must be requested and approved on a per-organization basis through the Anthropic sales team [1][2][4]. The policy applies to the following products, subject to approval and specific enablement: 1. Eligible Anthropic APIs [2][3] 2. Anthropic products using a Commercial organization API key (including Claude Code accessed via the API) [2][3] 3. Claude Code when used through a Claude for Enterprise plan (with ZDR specifically enabled for that organization) [1][2][4] Crucially, standard Claude Teams and Claude Enterprise chat product interfaces are not eligible for ZDR [1][3]. For Claude for Enterprise, administrators have control over standard data retention settings (with a 30-day minimum) rather than ZDR [3][5]. Additionally, enablement of ZDR is not automatic for new organizations created under an existing account; it must be requested separately for each new organization [1][4]. Note that for ZDR-eligible arrangements, Anthropic still retains User Safety classifier results to enforce its Usage Policy [2]. Organizations using Claude via third-party cloud platforms (e.g., Amazon Bedrock, Google Cloud, or Microsoft Foundry) should refer to those specific platforms' policies, even if using an Anthropic model [1][4][6]. top_results: [1][2][4][3][5]
Citations:
🌐 Web query:
OpenAI API data usage policies 30 days retention endpoint exceptions zero data retention official💡 Result:
OpenAI's standard data retention policy for API usage dictates that customer content—such as prompts and responses—is retained for up to 30 days in abuse monitoring logs to facilitate safety and abuse detection [1][2]. This retention period applies by default unless a longer period is legally required or necessary to protect services from harm [1]. Zero Data Retention (ZDR) is a control that, once approved and configured, excludes customer content from these abuse monitoring logs [1][3]. ZDR is subject to prior approval by OpenAI and the acceptance of additional requirements [1]. Key aspects of ZDR include: Endpoint Eligibility: ZDR is not available for all endpoints [1]. Stateless endpoints, such as /v1/chat/completions, /v1/responses, and /v1/realtime, are generally eligible for ZDR [1][4]. Conversely, stateful endpoints that support persistent sessions or long-term management—such as the /v1/conversations, /v1/conversations/items, and Assistants-related APIs—are generally ineligible for ZDR, and content processed through them may be retained until the customer deletes it [1][4][3]. Legal and Safety Exceptions: Even with ZDR enabled, OpenAI maintains mandatory exceptions for legal compliance [1][4]. Specifically, OpenAI is required by law to report potential instances of child sexual abuse material (CSAM), and data flagged for such risks will be retained regardless of ZDR status to support manual review and mandatory reporting [4]. Data for Training: For API customers, OpenAI does not use inputs or outputs to train its models by default [5]. This protection is standard for the API platform, regardless of whether ZDR is enabled [5]. Management: Organizations can manage their retention settings via the OpenAI API, where they may configure project-level retention types such as zero_data_retention or modified_abuse_monitoring [6]. Customers interested in ZDR should contact OpenAI sales to discuss eligibility and requirements [3].
Citations:
Document the exact provider-retention scope.
Line 56 omits the products, endpoints, approval requirements, and exceptions covered by the Deepnote agreements. Anthropic’s zero-data-retention terms apply only to eligible approved products and retain safety-classifier results. OpenAI’s 30-day period is a default abuse-monitoring limit with endpoint and eligibility exceptions. State the applicable scope.
🤖 Prompt for AI Agents
Source: MCP tools