1. Encryption
- In transit: TLS 1.2 or higher on every public endpoint, with modern cipher suites, HSTS, and certificate pinning where feasible.
- At rest: AES-256 or an equivalent standard for stored personal information, evidence attachments, and backups.
- Key management: centrally managed hardware-security-module or KMS-backed keys, with periodic rotation, separation of duties, and access logging.
2. Access controls
- Role-based access controls with least-privilege defaults, separation of duties, and regular access reviews.
- Mandatory multi-factor authentication for all internal accounts.
- Just-in-time production access with full session recording for privileged actions.
3. Network and platform security
- Segmented production environments, private networking, and default-deny firewall policies.
- DDoS mitigation, rate limiting, and bot-management at the edge.
- Continuous vulnerability scanning, dependency monitoring, and timely patching.
4. Application security
- Secure software development lifecycle with code review, static analysis, and dependency scanning.
- Regular third-party penetration testing of high-risk surfaces.
- Comprehensive input validation, output encoding, and framework-level defenses against OWASP Top 10 categories.
5. Logging, monitoring, and audit
- Immutable audit logs for reviewer decisions, evidence changes, permissible-purpose certifications, and privileged administrative actions.
- Centralized security monitoring with alerting on anomalous behavior.
- Retention aligned to legal and consumer-reporting obligations.
6. Vendor and subprocessor management
Subprocessors are vetted for security, privacy, and reliability. Each is bound by written data-processing terms. See the current Subprocessors list.
7. Incident response and breach notification
We maintain a written incident response plan with defined roles, escalation paths, forensic evidence preservation, and regulator and customer notification workflows. Where a personal data breach is reasonably likely to result in a risk to the rights or freedoms of individuals, we notify the relevant supervisory authorities and, where required, affected individuals without undue delay and, where feasible, within the statutory windows applicable to the incident (including 72 hours under GDPR Article 33 and the notification windows under applicable U.S. state breach notification laws).
8. Business continuity and disaster recovery
We operate a resilient infrastructure with redundant availability zones, encrypted backups, and periodic restore testing. Recovery point and recovery time objectives are documented and reviewed.
9. Employee security
Employees complete background checks where lawful, sign confidentiality obligations, and receive privacy and security training on hire and annually. Access is revoked promptly upon role change or departure.
10. Physical security
Data centers operated by our infrastructure providers maintain 24/7 physical security, restricted access, biometric or badge controls, environmental monitoring, and independent attestations (including SOC 2 Type II and ISO/IEC 27001 where applicable).
11. Responsible disclosure
We welcome reports of vulnerabilities from good-faith security researchers. Report findings to security@hubordub.com with a description, reproduction steps, and proof of impact. Please avoid accessing accounts other than your own, disrupting the Services, or exfiltrating personal data. We will acknowledge receipt within two (2) business days and provide status updates during triage. We do not pursue legal action against researchers who act in good faith and comply with this policy.
12. Contact
Hub or Dub Inc., Security, security@hubordub.com.
