Encryption with per-file keys, permissions that follow responsibility, and a tamper-evident ledger under every action. We are honest about what is certified and what is not — the documentation is yours to inspect during procurement.
We do not hold a SOC 2 Type II report or an ISO 27001 certificate today. Formal third-party audits are on our certification roadmap.
Per-file keys under HydraShield, our post-quantum-ready encryption layer. Backups and exports carry the same protection.
Role-based permissions with least privilege by default. Every read, share and export is logged, so you can prove who saw what — and who did not.
AI acts inside your permissions on your workspace content. We do not train on customer data and do not allow provider retention; prompts and outputs stay in your tenant.
Paid plans are advertising-free; free and discounted tiers may carry promotional placements. Client data is never sold, shared with advertisers or used for profiling on any plan.
Production servers in Singapore today, EU and US regions planned for Q4 2026. If a jurisdiction is mandated, we host your data there and set it out in your DPA.
Our staff cannot browse your tenant. Access requires named approval, is time-bound and appears in your own audit log — not just ours.
GDPR-compliant DPA, sub-processor list, controls mapping, architecture overview and evidence pack available during review.
Cancel whenever you want: full export of every record, file and audit log in JSON, CSV and PDF within 48 hours. Your evidence is yours, not ours.
Every action writes an entry: who did it, when, to which record, under which permission. Entries are hashed and chained, so altering history breaks the chain and shows. Exports carry the same hashes, which is what makes an audit pack verifiable rather than merely printed.
| Area | Today | On the roadmap |
|---|---|---|
| Encryption | TLS 1.3 in transit; AES-256 at rest with per-file keys (HydraShield) | Customer-managed keys (BYOK) for Enterprise |
| Hosting | Production servers in Singapore; jurisdiction-specific hosting on request | EU and US regions planned Q4 2026 |
| Identity | SSO / SAML on Growth and above; MFA on all plans | SCIM provisioning for Enterprise |
| Audit logging | Tamper-evident ledger on every plan; retention 30 days to 5 years | Customer-defined retention on Enterprise |
| AI governance | Actions run inside permissions, fully logged; no training on customer data | Bring-your-own-model (BYOM) for Enterprise |
| Certifications | SOC 2-aligned controls; ISO 27001-ready architecture; GDPR compliant | Formal SOC 2 and ISO 27001 audits on the certification roadmap |
| Testing | Third-party penetration testing; summary available under NDA | Continuous scanning with published cadence |
| Continuity | Encrypted backups with documented restore procedure | Multi-region failover once EU and US regions are live |
HubSecure is built on SOC 2-aligned controls and an ISO 27001-ready security architecture from day one. Formal third-party audits are on our certification roadmap, and every design partner gets full access to our security documentation, controls mapping and evidence pack during procurement review. Roadmap dates are targets, not guarantees.
DPA, sub-processor list, controls mapping and evidence pack are ready for review. If your regulator requires data in a specific jurisdiction, we will host it there and write it into the agreement.