Skip to main content
Security

Security & Trust Standards

This page describes the administrative, technical, and physical safeguards Hub or Dub applies to protect personal information and to maintain the integrity of the manually verified evidence that underlies every HOD Report and HOD Score.

Effective July 31, 2026 · Version 2026-07-31.1 · Continuously reconciled against local law

1. Encryption

  • In transit: TLS 1.2 or higher on every public endpoint, with modern cipher suites, HSTS, and certificate pinning where feasible.
  • At rest: AES-256 or an equivalent standard for stored personal information, evidence attachments, and backups.
  • Key management: centrally managed hardware-security-module or KMS-backed keys, with periodic rotation, separation of duties, and access logging.

2. Authentication and session security

  • Modern password hashing, screening of credentials against known-breach corpora, and rate-limited sign-in with lockouts.
  • Short-lived access tokens, session rotation, and prompt revocation on sign-out, password change, or role change.
  • Step-up verification for sensitive actions, including account recovery, ownership changes, and privileged back-office access.

3. Access controls

  • Role-based access controls with least-privilege defaults, separation of duties, and regular access reviews.
  • Database-level authorization (row-level security) so access limits are enforced by the data layer, not only by the interface.
  • Mandatory multi-factor authentication for all internal accounts.
  • Just-in-time, time-boxed production and consumer-account access with full logging of privileged actions.

4. Network and platform security

  • Segmented production environments, private networking, and default-deny firewall policies.
  • DDoS mitigation, rate limiting, and bot-management at the edge.
  • Continuous vulnerability scanning, dependency monitoring, and timely patching.

5. Application security

  • Secure software development lifecycle with code review, static analysis, and dependency scanning.
  • Regular third-party penetration testing of high-risk surfaces.
  • Comprehensive input validation, output encoding, parameterized database access, and framework-level defenses against OWASP Top 10 categories, including injection, broken access control, and authentication weaknesses.
  • Server-side authorization on every privileged operation; privileged credentials are never exposed to the browser.

6. Data protection and minimization

  • Sensitive identifiers such as Social Security Numbers, ITINs, and FEINs are stored encrypted and matched through a one-way index; full values are not displayed in the interface or returned by public endpoints.
  • Personal information is collected only where a verification, dispute, billing, or legal obligation requires it, and is segregated from general account data.
  • Retention is aligned to consumer-reporting, tax, and other legal obligations, after which records are deleted or de-identified.

7. Logging, monitoring, and audit

  • Immutable audit logs for reviewer decisions, evidence changes, permissible-purpose certifications, and privileged administrative actions.
  • Centralized, continuous security monitoring with alerting on anomalous behavior and real-time escalation to supervisors.
  • Retention aligned to legal and consumer-reporting obligations.

8. Abuse and threat prevention

Our controls are designed to reduce the likelihood and impact of unauthorized access, credential abuse and stuffing, account takeover, data exposure, injection attacks, scraping, and other automated attacks. Safeguards include rate limiting, lockouts, bot mitigation, anomaly detection, notification of sensitive account changes, human review before ownership of a record changes, and mandatory logging of privileged access.

9. Privacy by design

Privacy requirements are evaluated at design time, not after launch. Systems default to the minimum data necessary, restrict internal visibility of sensitive fields, mask identifiers in the interface, and record the purpose and actor for each access to consumer information. See our Privacy Policy and U.S. State Privacy Rights notice.

10. Vendor and subprocessor management

Subprocessors are vetted for security, privacy, and reliability. Each is bound by written data-processing terms. See the current Subprocessors list.

11. Incident response and breach notification

We maintain a written incident response plan with defined roles, escalation paths, forensic evidence preservation, and regulator and customer notification workflows. Where a data breach is reasonably likely to result in a risk to the rights of individuals, we notify the relevant state regulators and, where required, affected individuals without undue delay and, where feasible, within the notification windows required under applicable U.S. state breach notification laws.

12. Business continuity and disaster recovery

We operate a resilient infrastructure with redundant availability zones, encrypted backups, and periodic restore testing. Recovery point and recovery time objectives are documented and reviewed.

13. Employee security

Employees complete background checks where lawful, sign confidentiality obligations, and receive privacy and security training on hire and annually. Access is revoked promptly upon role change or departure.

14. Physical security

Data centers operated by our infrastructure providers maintain 24/7 physical security, restricted access, biometric or badge controls, environmental monitoring, and independent attestations (including SOC 2 Type II and ISO/IEC 27001 where applicable).

15. Continuous improvement

Security practices are reviewed on a recurring cycle and updated as threats evolve, as the Services change, and as vulnerabilities are reported. This page describes the safeguards Hub or Dub Inc. maintains; it is not a certification, attestation, or warranty of any particular outcome.

16. Responsible disclosure

We welcome reports of vulnerabilities from good-faith security researchers. Report findings to security@hubordub.com with a description, reproduction steps, and proof of impact. Please avoid accessing accounts other than your own, disrupting the Services, or exfiltrating personal data. We will acknowledge receipt within two (2) business days and provide status updates during triage. We do not pursue legal action against researchers who act in good faith and comply with this policy.

17. Contact

Hub or Dub Inc., Security, security@hubordub.com.

Contact, consumer requests, and disputes

Hub or Dub Inc. is a U.S. consumer reporting agency operating in all 50 states and U.S. territories. Hub or Dub Inc., HOD Scoring & Reporting Inc., HOD Investigations Inc., HOD Clubs Inc., HOD Investments Inc., and HOD Technologies Inc. are all 100% owned and operated by Stutson Global Inc. under the Stutson Family Trust, a Nevada based irrevocable trust that is owned and controlled privately by the Stutson family. Hub or Dub operates independently as a private-sector organization and is not a government agency, government-sponsored entity, law-enforcement agency, or governmental representative. Hub or Dub Inc.'s National Headquarters is located at 101 6th Avenue, 9th Floor, New York, New York 10013, with remote operations across the United States and all U.S. territories. Hub or Dub Inc. is an independent private company and has no direct partnership, affiliation, endorsement, sponsorship, agency relationship, contractual relationship, or other formal relationship with any federal, state, local, territorial, or foreign government, government agency, governmental authority, or foreign governmental entity, unless expressly disclosed in writing by Hub or Dub.

No physical mail. Hub or Dub Inc. does not currently accept in-person visits to its National Headquarters. All inquiries must be submitted online through the appropriate channels provided. Customer support, identity verification, reporting, investigations, disputes, and service delivery are conducted remotely through Hub or Dub's approved digital channels. Physical mail, walk-ins, document drop-offs, and on-site appointments are not accepted and cannot be processed. Please scan and email all documentation to help@hubordub.com, or use secure upload and support ticketing inside your account. Hub or Dub does not provide telephone support or live chat. Please scan all documentation and email it to help@hubordub.com so it can be logged, verified, and tied to your file record.

Applicable compliance, security, and privacy commitments

Built for FCRA Compliance.
Hub or Dub operates as a consumer reporting agency under a written FCRA compliance framework covering permissible purpose, accuracy procedures, disclosures, disputes, and adverse action support. Read the policy.
U.S. Consumer Reporting Compliance.
Reports, disclosures, and reinvestigations follow documented consumer reporting procedures aligned with the FCRA and applicable state consumer reporting laws. Read the policy.
Consumer Rights Disclosure.
Your rights under the Fair Credit Reporting Act, including file access, disputes, and adverse action notices, are published in plain language. Read the policy.
Consumer Dispute & Correction Rights.
Any consumer can dispute information free of charge. Disputes are reinvestigated by a human reviewer and corrections are applied to the record. Read the policy.
Responsible Data Practices.
Data minimization, purpose limits, retention schedules, and documented subprocessors govern how information is collected and used. Read the policy.
We Do Not Sell Your Personal Data.
Hub or Dub does not sell personal information and does not share it for cross-context behavioral advertising. Read the policy.
Encrypted in Transit & at Rest.
Submissions, documents, and account data are encrypted in transit with TLS and encrypted at rest by our infrastructure providers. Read the policy.
SSL/TLS Secured Connection.
All traffic to Hub or Dub is served over HTTPS with modern TLS and HSTS. Plaintext connections are not accepted. Read the policy.

These indicators describe Hub or Dub's own published policies, procedures, and technical controls. They are self-attested and are not government certifications, licenses, accreditations, or endorsements. Hub or Dub is a private company and is not affiliated with any government agency.