
Compliance
W&B Multi-tenant Cloud’s hosting platform meets the requirements of the Service and Organization Controls (SOC) 2 Type 2, published by the Auditing Standards Board of the American Institute of Certified Public Accountants (AICPA). A SOC 2 report evaluates a service organization’s controls for security, availability, processing integrity, confidentiality, and privacy. W&B Multi-tenant Cloud is subject to periodic internal and external audits to verify continued compliance. Refer to the W&B Security Portal to request the SOC 2 report and other security and compliance documents.W&B Multi-tenant Cloud does not meet the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). If your organization is subject to HIPAA, consider W&B Dedicated Cloud instead.
Data security
For users on Free or Pro plans, all data is only stored in the shared cloud storage and is processed with shared cloud compute services. Depending on your pricing plan, you may be subject to storage limits. Users on an Enterprise plan can bring their own bucket (BYOB) using the secure storage connector at the team level to store their files such as models, datasets, and more. You can configure a single bucket for multiple teams or you can use separate buckets for different W&B Teams. If you do not configure BYOB for a team, the team’s data is stored in the shared cloud storage. You are responsible for ensuring that your deployment complies with your organization’s policies and Security Technical Implementation Guidelines (STIG), if applicable.Identity and access management (IAM)
If you are on an Enterprise plan, enhanced identity and access managements capabilities allow for secure authentication and effective authorization for your W&B deployment:- SSO authentication with OIDC or SAML. Reach out to your W&B team or support if you would like to configure SSO for your organization.
- Configure appropriate user roles at the scope of the organization and within a team.
- Define the scope of a W&B project to limit who can view, edit, and submit W&B runs to it with restricted projects.
Monitor
Organization admins can manage usage and billing for their account from theBilling tab in their account view. If using the shared cloud storage on Multi-tenant Cloud, an admin can optimize storage usage across different teams in their organization.