Once notebooks have been created, they are just json files that get rendered to html so there's no haskell or python code running. If you're allowing other people to upload notebooks though, you'll want to sandbox them inside an iframe to prevent xss attacks - at work we do this, but allow some channels of communication using the postmessage API.