We're not going to say "bank-grade security" and leave it at that. This page breaks every mechanism down to something you can actually check: who holds the credentials, how many steps a wipe takes, how credits are calculated, and where your data physically lives. Read it, verify it yourself, then decide whether to pay.
You get a whole Mac mini, not a slice of a VM. There's no hypervisor, no shared disk, no neighbors — most multi-tenant risks simply don't exist at the physical layer.
CPU, unified memory, NVMe, and the 1Gbps port are all exclusively yours. No steal time, no noisy neighbors — build-time variance comes from your code, not someone else's workload. Cross-tenant side-channel attacks (cache timing, shared-page deduplication) simply don't apply on single-tenant dedicated hardware.
Your SSH key, VNC password, and macOS admin password belong to you and can be rotated anytime. We don't hold back an account, a public key, or a management agent — our own team has no technical path into your system. Details in "Access Control" below.
After expiration, data is held for 72 hours so you can renew or grab a snapshot. Once the window closes, a two-step wipe kicks in: the APFS encrypted volume key is destroyed, then the whole disk is overwritten. Every machine goes through a fresh install and a self-check before it's re-provisioned — there's no such thing as "leftovers from the last tenant."
Every node runs 365 days a year — we never take instances offline to service them. Uptime is measured minute-by-minute via out-of-band power monitoring, with figures synced to the status page daily.
Only one anomaly in the last 90 days: the greyed-out cell marks 11 minutes of upstream link jitter at the Tokyo node. Monthly uptime still landed at 99.97%, below the credit threshold. All other 89 days ran at 100% uptime across every node.
| Actual monthly uptime | Credit |
|---|---|
| ≥ 99.9% | Target met, no credit |
| 99.8% – 99.9% | 1 day |
| 99.7% – 99.8% | 2 days |
| 99.0% – 99.7% | 1 day per 0.1% below target, up to 9 days in this range |
| < 99.0% | Same accrual rule, capped at 100% of the paid period |
Open a ticket in the control panel with your instance ID and the outage window. We verify against raw out-of-band monitoring data and post the result within 7 business days; you can export the underlying data from the ticket at any time.
Only two exclusions apply: actions on your side (accidentally breaking your own firewall rules, shutting the machine down yourself, misconfiguring your system) and force majeure. There's no "routine maintenance" exclusion — because we don't schedule that kind of downtime in the first place. Full terms in our Terms of Service.
"Deleted" isn't good enough as an answer. It's a timestamped pipeline where every step is verifiable through your ticket history.
An instance that isn't renewed is immediately powered down and disconnected from the public network, with disk data left untouched. Renew at this point and the machine powers back on with your data exactly as you left it.
Within 72 hours you can renew anytime, or trigger a snapshot download from the control panel to take your data with you. Once the window closes, the instance enters the wipe queue and can no longer be recovered.
The data volume has been an APFS encrypted volume since day one. Destroying the volume key takes about 1 second, and from that moment every byte of ciphertext on disk is cryptographically unrecoverable — the first and fastest layer of protection.
The entire NVMe drive is overwritten with random data and verified sector by sector, defending against any theoretical attack on leftover ciphertext. Overwrite logs are retained for 90 days for audit purposes.
A clean macOS install goes on, and the machine only re-enters the available pool after passing SMART and memory self-checks. The next tenant gets a factory-state system.
We recommend handling your data at least 24 hours before expiration: generate and download a snapshot with one click in the control panel, or use rsync to sync your project directory back home. The machine stays available while a snapshot is being generated.
Early cancellation (a refund within the first 24 hours, or releasing an instance on your own) follows the exact same wipe pipeline — T+0 just starts the moment you click "release," and the 72-hour retention window still applies.
Retention periods for logs and billing records (access logs: 90 days; billing records: 7 years) are covered in our Privacy Policy.
The most common security-review question is "can your staff see my data?" The answer is no — and it's a technical no, not a policy no.
dscl . list /Users
profiles list comes back empty
You get a security baseline at delivery, not a "go live naked and harden it yourself" experience. All three layers of protection are included in the price — no extra charge.
The upstream ACL allows only 22/TCP (SSH) and 5900/TCP (VNC) inbound by default; everything else inbound is denied, and outbound is unrestricted. Add or remove port rules yourself from the control panel — changes take effect within 60 seconds — or disable the template entirely and run your own pf rules.
All five node entry points run traffic scrubbing that auto-mitigates common patterns like SYN, UDP, and ICMP floods — no configuration required on your end. Your legitimate SSH/VNC sessions stay reachable even when large-scale mitigation kicks in, and scrubbing events are logged in the ticket system.
Renting multiple machines at the same node? Apply for free private networking to get a dedicated internal subnet, so inter-machine traffic stays off the public interface entirely. Great for topologies like "one machine dispatching GitLab Runner jobs to several build machines" — private traffic is billed the same as public traffic (i.e., not at all).
The first rule of supply chain security is touching things as little as possible: we don't open machines, we don't modify them, and we don't mix parts. Every unit goes from box to rack in factory condition.
Every Mac mini is purchased brand-new through official Apple channels, with purchase records and serial numbers archived one-to-one. Your delivery email includes the machine's serial number so you can independently verify activation status and warranty coverage on Apple's own site.
The M4 series' unified memory and SSD are soldered on the board — there's nothing to "upgrade" in the first place. We commit to never opening the case or swapping any component. The hardware info you see in-system (system_profiler SPHardwareDataType) is the whole truth about that machine.
Hardware failures aren't repaired in place — we swap in a same-model unit from our standing spare pool. The faulty machine goes through the standard wipe pipeline, and your new machine is restored from your latest snapshot. Target time from confirmed failure to new credentials delivered: within 4 hours.
Machines are secured in dedicated racks, and data center access requires badge entry plus two-person escort. Rack access logs and video are retained for 90 days. No one touches a leased machine outside of a hardware replacement.
Every compliance claim comes with a way to verify it. If you're running a security review, feel free to paste the table below directly into your audit questionnaire.
| Item | Mechanism | How to verify |
|---|---|---|
| Data center certification | All five node data centers hold ISO 27001 certification, meet Tier III+ standards, and run dual-path power | Request the certificate number for your node via a support ticket and check it against the issuing body's public registry |
| Data residency | Your host data stays in the data center for the node you chose — no cross-region replication or off-site backup; snapshots only leave the facility when you actively download them | Run tcpdump against your instance's outbound traffic, or request a data-flow explanation via ticket |
| Platform-side log boundaries | We log only account, billing, out-of-band power actions, and network metering data — never files, processes, or screen content on your host | Cross-check against our Privacy Policy line by line; access logs auto-purge after 90 days |
| GDPR deletion requests | Account data deletion requests are completed within 30 days; deleting an active instance triggers the standard wipe pipeline immediately | Email support@oncemini.com — the reply includes a timestamp for every completed step |
| Governing jurisdiction | Disputes are governed by the law of the jurisdiction where the operating entity is based, as stated in our public terms | See the governing law clause in our Terms of Service |
Need a signed security statement or a custom audit questionnaire for procurement? Open a ticket in the control panel marked "security audit" and we'll answer every item — typically within 3 business days.
Security that holds up under inspection should also hold up under attack. Responsible disclosure is welcome — here's the process and timeline.
Please include reproduction steps and scope of impact in your email; if you need encrypted transmission, request our PGP public key first. Confirmed valid reports earn 7–30 days of rental credit depending on severity, plus a listing in our acknowledgments (anonymity available on request).
In scope: the oncemini.com main site, the Console control panel, the api.oncemini.com API, and default configuration flaws in delivered images or firewall templates.
Out of scope: any testing against a live instance belonging to another user, denial-of-service style stress testing, social engineering or phishing, or anything requiring physical access to a data center. Testing your own rented instance is fair game — it's yours to do with as you like.
Good-faith research that stays within these boundaries will never result in legal action or account suspension on our part.
$ rent --chip m4 --wipe-on-exit
Daily rentals start at $19.9, refundable within the first 24 hours. You'll get SSH credentials within 5 minutes of checkout — check every claim on this page yourself, starting right there.