For IT and security teams. A summary of how Notate protects your organization's documents, for use in a security review. For the technical detail, see Notate for Intune Data Flow, the Solution Architecture Guide and Notate Sharing Architecture.
Architecture
|
Area |
How Notate handles it |
|---|---|
|
Client application |
Notate is a containerized productivity app, deployed and managed through your MDM (for example Microsoft Intune). It connects to your on-premises Exchange server, or to Microsoft 365 through Microsoft Graph. Notate Desktop, for Windows and Mac, runs in the browser but executes entirely on the user's computer, in the same way as the mobile app. |
|
Data storage |
All data stays in your organization's environment: the user's OneDrive (in the Notate Drive folder), Exchange, SharePoint, Teams, or your file shares. Notate does not transmit or store customer data on Shafer Systems infrastructure. |
|
Authentication |
Your Exchange server or Microsoft Entra ID, together with your MDM, handles user identity and authorization. With Microsoft 365, sign-in uses OAuth 2.0 and your Conditional Access policies. |
|
Encryption |
All network communication uses TLS 1.2 or later. Local storage is encrypted using the iOS Keychain and the Android Keystore. |
Threat model summary
|
Threat |
Mitigation |
|---|---|
|
Data leakage |
Containerization enforced by your MDM's app protection policies (for example Intune App Protection Policies). No data leaves the app except through channels you approve. |
|
Unauthorized access |
Microsoft authentication (OAuth 2.0), with optional multifactor authentication and device compliance checks. |
|
Code vulnerabilities |
Static code analysis (Snyk, Veracode) and dependency scanning on each release. |
|
Man-in-the-middle attacks |
TLS 1.2 or later, with certificate pinning on sensitive endpoints. |
|
Data left on the device |
Encrypted app sandbox. Data is wiped when the device is unenrolled or the app is removed. |
Secure development and testing
-
Regular static code analysis and dependency vulnerability scanning.
-
Enterprise customers in banking and technology have performed independent penetration tests of Notate. All critical, high and medium findings from those assessments were fixed.
-
Shafer Systems does not currently commission an independent penetration test every year. We support customer-initiated testing and provide engineering access and cooperation to verify fixes.
-
Development follows the OWASP Mobile Security Testing Guide (MSTG) and the OWASP Mobile Top 10.
Software bill of materials (SBOM)
-
Dependencies are tracked and monitored for CVEs with Snyk.
-
All third-party libraries are open-source or commercially licensed components with no known critical vulnerabilities at the time of release.
Compliance and customer vetting
Notate is deployed in government agencies and financial institutions that perform their own independent information security reviews.