Security without the theatre.

Encryption, role-based access, audited controls and a sub-processor list you can actually read. Here is exactly what we do.

SOC 2

Type II, audited annually

GDPR

DPA + SCCs available

HIPAA

BAA on Enterprise plans

99.9%

Uptime SLA, Enterprise

How your data is protected.

The controls that matter, stated plainly.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, including database backups and screenshot storage.

Role-based access

Permissions resolve per organization, team and member. Every access is logged and reviewable.

SSO & SCIM

SAML single sign-on and automatic provisioning via Okta, Entra ID or any SAML 2.0 provider.

Data residency

Choose a US or EU region for your organization’s data at signup, or on request afterwards.

Least-privilege support

Huble staff access customer data only on an approved support ticket, time-boxed and logged.

Tested, not assumed

Annual third-party penetration test plus continuous automated dependency scanning.

FAQs

Can we get your SOC 2 report?

Yes — the current Type II report is available under NDA. Request it from the contact page.

Where is our data stored?

In the region your organization selects: US (us-east) or EU (eu-central), on AWS. See our sub-processor list for the full set.

Do you support single sign-on?

Yes, SAML 2.0 SSO plus SCIM provisioning. Available on Team and Enterprise plans.

How do you handle a security incident?

Confirmed incidents affecting customer data are reported to org admins within 72 hours, per our DPA, with a written post-incident summary.

Can we run a penetration test against Huble?

Yes, with scheduling agreed in advance. Contact us to arrange scope and timing.

The paperwork.

Everything referenced on this page, in writing.

Bring your security team.

We will walk them through controls, architecture and the SOC 2 report.