Built for files
you didn’t write.
How MLGatee protects your models, your keys and your callers.
Never loaded on our servers
The inspector reads your file’s bytes to find what it needs. It never loads the model, so code hidden in a pickle never runs on our servers.
One service per model
Each model runs in its own service with its own packages, shared with no other model. This isolation is the real protection.
Keys shown once
Endpoint keys are stored only as a SHA-256 hash and the last four characters. A new key takes over once the rebuild is live.
Private storage
Files go straight to a private bucket through a single-use upload link. Services fetch them with short-lived signed links.
Only your own data
Row-level security in the database means you can read only your own records, and only their safe columns.
Monitoring without inputs
Services report counts and timings only. Inputs, outputs, keys and headers are never recorded.
Checked package pins
Every package pin is checked against a strict pattern before it reaches a build, so nothing else can be injected.
Access tokens
Tokens for the Python client expire after 90 days, are stored as a hash, can’t create other tokens and can be revoked any time.
Backups and health checks
The database is backed up nightly, encrypted, and kept for 30 days. A daily check watches storage and builds.
The inspector is defense in depth, not a sandbox. Its rules are public along with the code. Per-model isolation is what keeps models apart, and it is never weakened.
Report a vulnerability
Found a security issue? Tell us privately and we’ll follow up. Please don’t disclose it publicly until it’s fixed.