Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Notate Security Overview

For IT and security teams. A summary of how Notate protects your organization's documents, for use in a security review. For the technical detail, see Notate for Intune Data Flow, the Solution Architecture Guide and Notate Sharing Architecture.

Architecture

Area

How Notate handles it

Client application

Notate is a containerized productivity app, deployed and managed through your MDM (for example Microsoft Intune). It connects to your on-premises Exchange server, or to Microsoft 365 through Microsoft Graph. Notate Desktop, for Windows and Mac, runs in the browser but executes entirely on the user's computer, in the same way as the mobile app.

Data storage

All data stays in your organization's environment: the user's OneDrive (in the Notate Drive folder), Exchange, SharePoint, Teams, or your file shares. Notate does not transmit or store customer data on Shafer Systems infrastructure.

Authentication

Your Exchange server or Microsoft Entra ID, together with your MDM, handles user identity and authorization. With Microsoft 365, sign-in uses OAuth 2.0 and your Conditional Access policies.

Encryption

All network communication uses TLS 1.2 or later. Local storage is encrypted using the iOS Keychain and the Android Keystore.

Threat model summary

Threat

Mitigation

Data leakage

Containerization enforced by your MDM's app protection policies (for example Intune App Protection Policies). No data leaves the app except through channels you approve.

Unauthorized access

Microsoft authentication (OAuth 2.0), with optional multifactor authentication and device compliance checks.

Code vulnerabilities

Static code analysis (Snyk, Veracode) and dependency scanning on each release.

Man-in-the-middle attacks

TLS 1.2 or later, with certificate pinning on sensitive endpoints.

Data left on the device

Encrypted app sandbox. Data is wiped when the device is unenrolled or the app is removed.

Secure development and testing

  • Regular static code analysis and dependency vulnerability scanning.

  • Enterprise customers in banking and technology have performed independent penetration tests of Notate. All critical, high and medium findings from those assessments were fixed.

  • Shafer Systems does not currently commission an independent penetration test every year. We support customer-initiated testing and provide engineering access and cooperation to verify fixes.

  • Development follows the OWASP Mobile Security Testing Guide (MSTG) and the OWASP Mobile Top 10.

Software bill of materials (SBOM)

  • Dependencies are tracked and monitored for CVEs with Snyk.

  • All third-party libraries are open-source or commercially licensed components with no known critical vulnerabilities at the time of release.

Compliance and customer vetting

Notate is deployed in government agencies and financial institutions that perform their own independent information security reviews.

Last updated: