Artifactive

Security

Artifactive authenticates every viewer through your company's identity provider. Viewers sign in with the credentials they already use for work. No shared passwords and no separate user directory.

Authentication

When someone opens a dashboard link, Artifactive redirects them to your IdP. Your IdP authenticates the user and returns a signed assertion. Artifactive checks the assertion, confirms the user's email domain matches your approved list, and grants access. Credentials never touch Artifactive directly.

Your existing MFA policies carry over. If your Okta or Entra configuration requires a second factor, viewers are prompted for it before they reach the dashboard.

Supported identity providers

Artifactive connects to any SAML 2.0-compatible identity provider.

Identity provider Protocol Setup guide
Google Workspace SAML 2.0 View Google Workspace setup →
Microsoft Entra ID (Azure AD) SAML 2.0 View Entra ID setup →
Okta SAML 2.0 View Okta setup →
Any SAML 2.0 provider SAML 2.0 View custom SAML setup →

Your IT team configures the IdP connection once. Every dashboard published after that uses the same setup.

Access control

Access is scoped by email domain. You approve one or more domains (e.g. yourcompany.com), and only users whose IdP-authenticated email matches can view dashboards. If someone outside the company gets hold of a link, they see a login screen that rejects them.

Publishers (the people uploading dashboards) are managed separately on a named-user basis.

Offboarding

When you disable an employee's account in your identity provider, they lose access to all Artifactive dashboards. Artifactive validates against your IdP on every new session, so a deprovisioned user cannot start one.

Data security

All connections use TLS 1.2 or higher. Dashboard files at rest are encrypted with AES-256 through AWS S3 server-side encryption.

Artifactive runs on AWS (US East). AWS maintains SOC 2 Type II and ISO 27001 certifications covering the underlying infrastructure. Documentation is available at aws.amazon.com/compliance.

What we store

Artifactive stores the HTML files you publish and the access metadata associated with them (who accessed which dashboard, when). We do not store viewer passwords. Authentication is handled entirely by your IdP.

Common questions

Does this work with our existing Okta / Google Workspace / Entra setup?

Yes. You configure a SAML 2.0 application in your IdP, point it at Artifactive, and provide the identity-provider metadata. The SAML setup reference covers the common fields.

Do viewers need an Artifactive account?

No. Viewers sign in through your IdP. Only publishers have Artifactive accounts.

What happens if the link leaks?

Anyone who clicks it sees a login prompt. If their email domain isn't approved, they can't get in. The URL alone gives no access.

Does Artifactive enforce MFA?

MFA is handled by your identity provider. Whatever policy you've set in Okta, Entra, or Google Workspace applies to Artifactive logins automatically.

Where is data hosted?

AWS US East. Files encrypted at rest with AES-256, in transit with TLS 1.2+.

Talk to us

For security questions, vendor risk assessments, or compliance documentation: security@artifactive.com