Skip to main content
Security

Built for the trust we ask for.

A HOD Report can change a decision, so Hub or Dub is built security first: strong encryption, hardened authentication, strict least-privilege access, continuous monitoring, and an audit trail on every privileged action, from the database all the way through the Back Office.

Hoddie, the official Hub or Dub mascot
TLS 1.2+
Every endpoint
AES-256
Data at rest
MFA
All internal accounts
30 min
Access grant expiry
Defense in depth

Four layers. Each assumes the last one failed.

At the edge

Traffic is filtered before it ever touches application code.

  • TLS 1.2 or higher on every public endpoint, with HSTS
  • DDoS mitigation, bot management, and edge rate limiting
  • Throttles on sign-in, code entry, lookups, and report submission
Controls

What is actually running.

Not aspirations. These are the safeguards in place on the platform today.

Encryption in transit and at rest

All traffic uses TLS 1.2+ with modern cipher suites. Stored data, evidence attachments, and backups are encrypted at rest. Sensitive identifiers such as SSN, ITIN, and FEIN are encrypted with a one-way blind index and never exposed through a public endpoint.

Secure authentication and sessions

Modern password hashing, leaked-credential screening, short-lived tokens, and rotating sessions. Internal accounts require multi-factor authentication and shift-bound sign-in before any account data can be reached.

Least privilege by default

Row-Level Security is enforced on every user-facing table, APIs are scoped to the caller, and privileged operations verify role before they run. Back Office employees see only accounts they hold an active, time-boxed grant for.

Hardened infrastructure

Application, database, and background workers run in segmented, provider-managed environments in United States regions with private networking, default-deny policies, automatic patching, and encrypted daily backups.

Storage and minimization

We collect what a verification actually requires, separate sensitive fields from general account data, mask identifiers to the last four digits in the interface, and retain records only as long as legal and consumer-reporting obligations require.

Continuous monitoring

Security telemetry, anomaly alerting, dependency scanning, and automated posture checks run continuously. Suspicious access patterns raise real-time supervisor alerts and open an investigation record.

End-to-end audit trail

Every Back Office action, including access grants, refunds, overrides, delegations, and profile edits, is logged with actor, target, IP, and reason. Logs are immutable to end users and reviewed by supervisors.

Ownership overrides with alerts

Any use of a master or ownership override is rate limited to 3 attempts per 15 minutes with a 30-minute lockout on failure, and fires real-time critical notifications to every active supervisor.

Identity verification for access

Before a Back Office employee can view a consumer account, we email a 6-digit code to the account owner. Codes are single use, limited to 3 per 24 hours, and grants expire in 30 minutes.

Certified shop coworkers in Hub or Dub tees greeting a customer at the counter
Human review, under logged and expiring access.
Human access

Nobody just opens your file.

Our people verify records by hand, so the riskiest surface on this platform is internal access. It is also the most tightly controlled.

  1. 1. Request

    An employee requests access with a stated reason tied to an open matter.

  2. 2. Owner notified

    A 6-digit code goes to the account owner's verified email. Single use, 3 per 24 hours.

  3. 3. Time boxed

    The grant opens for 30 minutes, then closes itself. No standing access to consumer records.

  4. 4. Recorded

    Actor, target, IP, and reason are written to an immutable log a supervisor reviews.

Threat model

What we design against.

Layered controls, not a single wall. Each safeguard assumes the one in front of it can fail.

Unauthorized access

Every read is scoped to the signed-in identity at the database layer, so a missing check in one screen cannot expose another person's record.

Credential abuse

Leaked-password screening, rate limiting, lockouts, and step-up verification on sensitive actions.

Injection attacks

Parameterized queries, strict schema validation on every server function, and output encoding across the interface.

Automated attacks

Edge rate limiting, bot mitigation, and throttles on lookups, sign-in, code entry, and report submission.

Account takeover

Session rotation, device and location anomaly checks, notifications on sensitive changes, and human review before ownership moves.

Data exposure

Sensitive identifiers stay encrypted and masked, privileged clients are never reachable from the browser, and access to them is logged.

Insider misuse

Just-in-time grants, owner-notified verification, supervisor alerts on overrides, and immutable logs that employees cannot edit.

Supply chain risk

Continuous dependency scanning, pinned builds, and prompt patching, with subprocessors bound by written data-processing terms.

Security is never finished. Controls, dependencies, and detections are reviewed on a recurring cycle and updated as threats change, as the platform changes, and as new risks are reported to us.

Incident response

If something goes wrong.

  1. Detect

    Continuous monitoring and anomaly alerting flag the event and open an investigation record automatically.

  2. Contain

    Sessions are revoked, grants are closed, and affected surfaces are isolated while forensic evidence is preserved.

  3. Assess

    Scope, data categories, and impacted individuals are determined against documented severity criteria.

  4. Notify

    Where a breach is reasonably likely to create risk, we notify regulators and affected individuals within applicable U.S. state windows.

  5. Remediate

    Root cause is fixed, detections are tightened, and the change is reviewed in the next security cycle.

Responsible disclosure

Found a vulnerability? Email a proof of concept to security@hubordub.com before disclosing publicly. We acknowledge within 2 business days, keep you updated through resolution, and credit reporters with permission.

No litigation for good-faith researchScope: hubordub.com and subdomainsOut of scope: DoS, spam, social engineering

hubordub.com and its subdomains, plus the authenticated application surfaces you can reach with your own account.

Denial of service, spam, social engineering of our people, physical testing, and automated scanner output with no demonstrated impact.

We acknowledge receipt within 2 business days and keep you updated through triage and resolution.

No, not against good-faith research that follows this policy. Please avoid accessing accounts other than your own and never exfiltrate personal data.

Security and privacy contact

For law enforcement requests, subpoenas, and preservation letters, contact legal@hubordub.com. For consumer disputes and record corrections, use the disputes portal.

This page describes the security controls Hub or Dub Inc. maintains. It is not a certification or attestation. See Trust Center for the full posture.