Built for the trust we ask for.
A HOD Report can change a decision. That's why every layer of Hub or Dub, from the database to the back office, is designed around least-privilege access, real-time auditing, and hardened override controls.

Encryption in transit and at rest
All traffic uses TLS 1.2+. Database volumes and backups are encrypted at rest. Sensitive identifiers (SSN, EIN) are stored only as one-way SHA-256 hashes and are never exposed through the public API.
Least-privilege access
Row-Level Security is enforced on every user-facing table. Back-office employees see only the accounts they have an active, time-boxed grant for. Column-level revokes keep hashed identifiers unreachable to end users.
Isolated infrastructure
Application, database, and background workers run in hardened, provider-managed environments in United States regions with automatic patching and daily backups.
End-to-end audit trail
Every back-office action, access grants, refunds, overrides, delegations, and profile edits, is logged with actor, target, IP, and reason. Logs are immutable to end users and reviewed by supervisors.
Ownership overrides with alerts
Any use of a master/ownership override is rate-limited (3 attempts / 15 min, 30-minute lockout on failure) and generates real-time notifications to every active supervisor with a critical severity flag.
Identity verification for access
Before a back-office employee can view a consumer account, we email a 6-digit code to the account owner. Codes are single-use, limited to 3 per 24 hours, and grants expire in 30 minutes.
Responsible disclosure
Found a vulnerability? Please email a proof-of-concept to security@hubordub.com before disclosing publicly. We acknowledge within 2 business days, keep you updated through resolution, and credit reporters (with permission) on our security page.
Security & privacy contact
For law enforcement requests, subpoenas, and preservation letters, contact legal@hubordub.com. For consumer disputes and record corrections, use the disputes portal.
