Trust and boundaries

Media jobs need boundaries, not hand-waving.

RenderMac's security model makes the pool, credential, lease, artifact, and webhook boundaries explicit so a buyer can reason about a job before it runs.

Read the privacy policyRead the API docs
Scope honestly: this page documents current controls and dogfood posture; it is not a SOC 2, ISO, or public-fleet certification claim.

Controls in the job path

Scoped access

API keys are organization-scoped and routes enforce role and pool boundaries.

Private capacity cells

Private-first-party and organization-private pools keep early workloads away from broad public supply.

Leases and heartbeats

Workers claim bounded jobs with expiry, progress, and liveness checks.

Artifact isolation

Outputs are verified and delivered through short-lived URLs.

Signed webhooks

Timestamped signatures and delivery IDs reject tampering and deduplicate retries.

Fail-closed gates

Payments, public capacity, workforce, and deployment credentials remain gated until evidence exists.

Before a broader launch

RenderMac still needs staged IAM, isolation, payment, physical-fleet, backup, migration, and rollback evidence before public provider capacity becomes a product promise. See the status surface and current Terms.

Related reading

Buyers evaluating trust: Start at enterprise and private render pools, then join the buyer waitlist.