1. Encryption
- In transit: TLS 1.2 or higher on every public endpoint, with modern cipher suites, HSTS, and certificate pinning where feasible.
- At rest: AES-256 or an equivalent standard for stored personal information, evidence attachments, and backups.
- Key management: centrally managed hardware-security-module or KMS-backed keys, with periodic rotation, separation of duties, and access logging.
2. Authentication and session security
- Modern password hashing, screening of credentials against known-breach corpora, and rate-limited sign-in with lockouts.
- Short-lived access tokens, session rotation, and prompt revocation on sign-out, password change, or role change.
- Step-up verification for sensitive actions, including account recovery, ownership changes, and privileged back-office access.
3. Access controls
- Role-based access controls with least-privilege defaults, separation of duties, and regular access reviews.
- Database-level authorization (row-level security) so access limits are enforced by the data layer, not only by the interface.
- Mandatory multi-factor authentication for all internal accounts.
- Just-in-time, time-boxed production and consumer-account access with full logging of privileged actions.
4. Network and platform security
- Segmented production environments, private networking, and default-deny firewall policies.
- DDoS mitigation, rate limiting, and bot-management at the edge.
- Continuous vulnerability scanning, dependency monitoring, and timely patching.
5. Application security
- Secure software development lifecycle with code review, static analysis, and dependency scanning.
- Regular third-party penetration testing of high-risk surfaces.
- Comprehensive input validation, output encoding, parameterized database access, and framework-level defenses against OWASP Top 10 categories, including injection, broken access control, and authentication weaknesses.
- Server-side authorization on every privileged operation; privileged credentials are never exposed to the browser.
6. Data protection and minimization
- Sensitive identifiers such as Social Security Numbers, ITINs, and FEINs are stored encrypted and matched through a one-way index; full values are not displayed in the interface or returned by public endpoints.
- Personal information is collected only where a verification, dispute, billing, or legal obligation requires it, and is segregated from general account data.
- Retention is aligned to consumer-reporting, tax, and other legal obligations, after which records are deleted or de-identified.
7. Logging, monitoring, and audit
- Immutable audit logs for reviewer decisions, evidence changes, permissible-purpose certifications, and privileged administrative actions.
- Centralized, continuous security monitoring with alerting on anomalous behavior and real-time escalation to supervisors.
- Retention aligned to legal and consumer-reporting obligations.
8. Abuse and threat prevention
Our controls are designed to reduce the likelihood and impact of unauthorized access, credential abuse and stuffing, account takeover, data exposure, injection attacks, scraping, and other automated attacks. Safeguards include rate limiting, lockouts, bot mitigation, anomaly detection, notification of sensitive account changes, human review before ownership of a record changes, and mandatory logging of privileged access.
9. Privacy by design
Privacy requirements are evaluated at design time, not after launch. Systems default to the minimum data necessary, restrict internal visibility of sensitive fields, mask identifiers in the interface, and record the purpose and actor for each access to consumer information. See our Privacy Policy and U.S. State Privacy Rights notice.
10. Vendor and subprocessor management
Subprocessors are vetted for security, privacy, and reliability. Each is bound by written data-processing terms. See the current Subprocessors list.
11. Incident response and breach notification
We maintain a written incident response plan with defined roles, escalation paths, forensic evidence preservation, and regulator and customer notification workflows. Where a data breach is reasonably likely to result in a risk to the rights of individuals, we notify the relevant state regulators and, where required, affected individuals without undue delay and, where feasible, within the notification windows required under applicable U.S. state breach notification laws.
12. Business continuity and disaster recovery
We operate a resilient infrastructure with redundant availability zones, encrypted backups, and periodic restore testing. Recovery point and recovery time objectives are documented and reviewed.
13. Employee security
Employees complete background checks where lawful, sign confidentiality obligations, and receive privacy and security training on hire and annually. Access is revoked promptly upon role change or departure.
14. Physical security
Data centers operated by our infrastructure providers maintain 24/7 physical security, restricted access, biometric or badge controls, environmental monitoring, and independent attestations (including SOC 2 Type II and ISO/IEC 27001 where applicable).
15. Continuous improvement
Security practices are reviewed on a recurring cycle and updated as threats evolve, as the Services change, and as vulnerabilities are reported. This page describes the safeguards Hub or Dub Inc. maintains; it is not a certification, attestation, or warranty of any particular outcome.
16. Responsible disclosure
We welcome reports of vulnerabilities from good-faith security researchers. Report findings to security@hubordub.com with a description, reproduction steps, and proof of impact. Please avoid accessing accounts other than your own, disrupting the Services, or exfiltrating personal data. We will acknowledge receipt within two (2) business days and provide status updates during triage. We do not pursue legal action against researchers who act in good faith and comply with this policy.
17. Contact
Hub or Dub Inc., Security, security@hubordub.com.
Contact, consumer requests, and disputes
Hub or Dub Inc. is a U.S. consumer reporting agency operating in all 50 states and U.S. territories. Hub or Dub Inc., HOD Scoring & Reporting Inc., HOD Investigations Inc., HOD Clubs Inc., HOD Investments Inc., and HOD Technologies Inc. are all 100% owned and operated by Stutson Global Inc. under the Stutson Family Trust, a Nevada based irrevocable trust that is owned and controlled privately by the Stutson family. Hub or Dub operates independently as a private-sector organization and is not a government agency, government-sponsored entity, law-enforcement agency, or governmental representative. Hub or Dub Inc.'s National Headquarters is located at 101 6th Avenue, 9th Floor, New York, New York 10013, with remote operations across the United States and all U.S. territories. Hub or Dub Inc. is an independent private company and has no direct partnership, affiliation, endorsement, sponsorship, agency relationship, contractual relationship, or other formal relationship with any federal, state, local, territorial, or foreign government, government agency, governmental authority, or foreign governmental entity, unless expressly disclosed in writing by Hub or Dub.
- General and consumer support: help@hubordub.com or a secure support ticket. Hub or Dub does not provide telephone support or live chat.
- File disclosure, disputes, and corrections: start a dispute — reinvestigated within 30 days (45 days where you add information during the reinvestigation).
- Your FCRA rights: Consumer rights · FCRA & CRA compliance
- Privacy and state privacy rights: privacy@hubordub.com · state privacy rights
- Security reports: security@hubordub.com
No physical mail. Hub or Dub Inc. does not currently accept in-person visits to its National Headquarters. All inquiries must be submitted online through the appropriate channels provided. Customer support, identity verification, reporting, investigations, disputes, and service delivery are conducted remotely through Hub or Dub's approved digital channels. Physical mail, walk-ins, document drop-offs, and on-site appointments are not accepted and cannot be processed. Please scan and email all documentation to help@hubordub.com, or use secure upload and support ticketing inside your account. Hub or Dub does not provide telephone support or live chat. Please scan all documentation and email it to help@hubordub.com so it can be logged, verified, and tied to your file record.