Scoped access
API keys are organization-scoped and routes enforce role and pool boundaries.
Trust and boundaries
RenderMac's security model makes the pool, credential, lease, artifact, and webhook boundaries explicit so a buyer can reason about a job before it runs.
API keys are organization-scoped and routes enforce role and pool boundaries.
Private-first-party and organization-private pools keep early workloads away from broad public supply.
Workers claim bounded jobs with expiry, progress, and liveness checks.
Outputs are verified and delivered through short-lived URLs.
Timestamped signatures and delivery IDs reject tampering and deduplicate retries.
Payments, public capacity, workforce, and deployment credentials remain gated until evidence exists.
RenderMac still needs staged IAM, isolation, payment, physical-fleet, backup, migration, and rollback evidence before public provider capacity becomes a product promise. See the status surface and current Terms.