Skip to content
huub.Huub home

Trust centre

Secrets never touch plaintext chat.

Capability-based access control and row-level security throughout, with a secrets manager so credentials are never pasted into a channel.

How it is built

Capability-based access

Access is granted as a capability against an object, not as a role that quietly accumulates permissions. Revoking one does not need a migration.

Row-level security throughout

Every query passes row-level security, including the ones the AI layer makes. Nothing can surface a record you could not open yourself.

Managed secrets

A built-in secrets manager holds credentials and they are referenced, never pasted. Nothing sensitive sits in plaintext in a channel.

No training on your data

Your workspace is context for answers, not training data. This holds on every plan, with no setting to get wrong.

Identity and device

SAML 2.0 SSO

  • Works against your existing identity provider.
  • Enforced per workspace, not per user.
  • Included on every paid plan.

SCIM 2.0 provisioning

  • Accounts are created and removed from your directory.
  • Nobody on your team creates a password.
  • Deprovisioning is immediate, and audited.

EMM device management

  • Device posture is checked before a session opens.
  • Managed devices only, where policy requires it.
  • Available on Enterprise.

Data loss prevention, not an add-on

Messages pass a policy gate before they are stored. Anything matching a secret pattern is redacted and replaced with a reference to the secrets manager, so the credential itself never lands in the channel.

Messagecontains a tokenPolicy gatepattern matchbefore storageChannel••••• redactedSecrets managerreferenced, not pastedThe credential never lands in the channel: the gate redacts it and stores a reference to the secrets manager instead.

Compliance status

  • SOC 2 Type II

    In progress. We do not claim it before the report is issued.

  • GDPR

    Compliant. DPA available on request, subprocessors listed publicly.

  • ISO 27001

    Planned. No timeline committed publicly yet.

  • Data residency

    EU and UK, chosen per workspace.

Questions

The things teams ask first.

Send this page to your security team.

They will ask about identity, residency and DLP. It is all here, and we would rather answer it early.

We use essential cookies only. Nothing to opt out of.