Security without the theatre.
Encryption, role-based access, audited controls and a sub-processor list you can actually read. Here is exactly what we do.
Type II, audited annually
DPA + SCCs available
BAA on Enterprise plans
Uptime SLA, Enterprise
How your data is protected.
The controls that matter, stated plainly.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, including database backups and screenshot storage.
Role-based access
Permissions resolve per organization, team and member. Every access is logged and reviewable.
SSO & SCIM
SAML single sign-on and automatic provisioning via Okta, Entra ID or any SAML 2.0 provider.
Data residency
Choose a US or EU region for your organization’s data at signup, or on request afterwards.
Least-privilege support
Huble staff access customer data only on an approved support ticket, time-boxed and logged.
Tested, not assumed
Annual third-party penetration test plus continuous automated dependency scanning.
FAQs
Can we get your SOC 2 report?
Yes — the current Type II report is available under NDA. Request it from the contact page.
Where is our data stored?
In the region your organization selects: US (us-east) or EU (eu-central), on AWS. See our sub-processor list for the full set.
Do you support single sign-on?
Yes, SAML 2.0 SSO plus SCIM provisioning. Available on Team and Enterprise plans.
How do you handle a security incident?
Confirmed incidents affecting customer data are reported to org admins within 72 hours, per our DPA, with a written post-incident summary.
Can we run a penetration test against Huble?
Yes, with scheduling agreed in advance. Contact us to arrange scope and timing.
The paperwork.
Everything referenced on this page, in writing.
Bring your security team.
We will walk them through controls, architecture and the SOC 2 report.