Claim your seat
HubSecure
Claim your seat
FOUNDING 100
40% off year one · price locked for life · first 100 regulated teams
— days to launch · August 11
Claim your seat →
Security & privacy

Your client data is what we protect — never what we sell.

Encryption with per-file keys, permissions that follow responsibility, and a tamper-evident ledger under every action. We are honest about what is certified and what is not — the documentation is yours to inspect during procurement.

Certification status — stated plainly
GDPR compliance In place
DPA & sub-processor list Available on request
ISO 27001 Architecture ready — not certified
SOC 2 Controls aligned — no report yet
Penetration testing Summary on request

We do not hold a SOC 2 Type II report or an ISO 27001 certificate today. Formal third-party audits are on our certification roadmap.

How it is protected

Eight commitments, written the way procurement reads them.

Encrypted in transit and at rest

Per-file keys under HydraShield, our post-quantum-ready encryption layer. Backups and exports carry the same protection.

Access follows responsibility

Role-based permissions with least privilege by default. Every read, share and export is logged, so you can prove who saw what — and who did not.

Your data never trains a model

AI acts inside your permissions on your workspace content. We do not train on customer data and do not allow provider retention; prompts and outputs stay in your tenant.

No ads on paid plans, ever

Paid plans are advertising-free; free and discounted tiers may carry promotional placements. Client data is never sold, shared with advertisers or used for profiling on any plan.

Residency where your rules require it

Production servers in Singapore today, EU and US regions planned for Q4 2026. If a jurisdiction is mandated, we host your data there and set it out in your DPA.

Support access is explicit and logged

Our staff cannot browse your tenant. Access requires named approval, is time-bound and appears in your own audit log — not just ours.

Procurement-ready documentation

GDPR-compliant DPA, sub-processor list, controls mapping, architecture overview and evidence pack available during review.

Leave anytime, take everything

Cancel whenever you want: full export of every record, file and audit log in JSON, CSV and PDF within 48 hours. Your evidence is yours, not ours.

The evidence ledger

Tamper-evident by construction, not by policy.

Every action writes an entry: who did it, when, to which record, under which permission. Entries are hashed and chained, so altering history breaks the chain and shows. Exports carry the same hashes, which is what makes an audit pack verifiable rather than merely printed.

Retention by plan 30 days → 5 years
Ledger entries · structure
Document sealed
MSA v4 · approved by M. Berg · 09:41:05
#0c4de2…
Access attested
3 roles · matter #2041 · 09:41:08
#77b1e9…
Screening completed
Party: Nordfjord AS · no hits · 09:44:12
#c2a4f1…
Audit pack exported
1,284 entries · JSON + PDF · 10:02:31
#e772b8…
Illustrative structure — not live customer data.
Operational posture

What we run, and what we promise.

Area Today On the roadmap
Encryption TLS 1.3 in transit; AES-256 at rest with per-file keys (HydraShield) Customer-managed keys (BYOK) for Enterprise
Hosting Production servers in Singapore; jurisdiction-specific hosting on request EU and US regions planned Q4 2026
Identity SSO / SAML on Growth and above; MFA on all plans SCIM provisioning for Enterprise
Audit logging Tamper-evident ledger on every plan; retention 30 days to 5 years Customer-defined retention on Enterprise
AI governance Actions run inside permissions, fully logged; no training on customer data Bring-your-own-model (BYOM) for Enterprise
Certifications SOC 2-aligned controls; ISO 27001-ready architecture; GDPR compliant Formal SOC 2 and ISO 27001 audits on the certification roadmap
Testing Third-party penetration testing; summary available under NDA Continuous scanning with published cadence
Continuity Encrypted backups with documented restore procedure Multi-region failover once EU and US regions are live

HubSecure is built on SOC 2-aligned controls and an ISO 27001-ready security architecture from day one. Formal third-party audits are on our certification roadmap, and every design partner gets full access to our security documentation, controls mapping and evidence pack during procurement review. Roadmap dates are targets, not guarantees.

Send us your security questionnaire.

DPA, sub-processor list, controls mapping and evidence pack are ready for review. If your regulator requires data in a specific jurisdiction, we will host it there and write it into the agreement.

Request the evidence pack Join the waitlist