Skip to content
Security & Trust — status console

Status: SOC 2 Type II. Continuous since Q3 2021.

HBHUD is built for leadership teams who can't guess on data stewardship. Our trust posture is the same as our product posture — observable, auditable, and updated the moment something changes. No email tag required.

SOC 2 II
since Q3 2021
24h
control-change SLA
GDPR · CCPA
compliant posture
47
monitored integrations
TRUST MACHINERY · 04 ARTIFACTS

The trust portal updates within 24 hours of any control change.

Marketing claims don't pass vendor risk review. We publish the four artifacts a reviewer pulls during diligence — live, with timestamps, no NDA gate.

01

Public trust portal

A live, versioned page listing every control in scope, its current owner, and when it was last reviewed. No login wall.

last sync 14m ago
02

24-hour control-change SLA

When a control is added, retired, or moved between owners, the trust portal reflects it within 24 hours. Verified by an internal CI check.

median latency 3h 41m
03

Named subprocessor list

Every third party that touches customer data, named with region and purpose. Customers are notified 30 days before any addition.

subprocessors 9 listed
04

Incident history, in the open

Past security incidents are published with timeline, root cause, and customer impact — even the boring ones. Zero since platform GA.

open incidents 0
ANSWER FIRST · WHAT WE ARE, WHAT WE AREN'T

What we are, what we aren't, and where your data lives.

CERTIFIED FOR

  • SOC 2 Type II. Continuously since Q3 2021. Annual report from an independent auditor, available under NDA.
  • GDPR. Lawful basis documented per data category; DPA available for signature in one click.
  • CCPA. Data subject access, deletion, and opt-out requests honored within statutory windows.

DELIBERATELY NOT

  • HIPAA. HBHUD is SOC 2 Type II only. If your workload carries PHI, route it through a separate BAA-covered layer.
  • A replacement for your warehouse. HBHUD sits on top of Snowflake, Databricks, BigQuery, and Postgres — we do not duplicate regulated source data.
  • A black box. Every query path, every dashboard refresh, every alert trigger is logged and replayable.

WHERE YOUR DATA LIVES

Primary region
US-East (AWS us-east-1, Virginia)
EU region
EU-West (AWS eu-west-1, Ireland) on request
Encryption at rest
AES-256, customer-managed keys optional
Encryption in transit
TLS 1.3 minimum, HSTS enforced
Backups
Hourly snapshots, 35-day retention, encrypted
DUE-DILIGENCE · FOUR DOCUMENTS

Four documents. No email tag. Download directly.

The exact artifacts a VP Product or a PE operator pulls during vendor review. Each one is current as of the timestamp printed on the cover page.

  1. 01

    SOC 2 Type II report

    Full Type II report covering the Security, Availability, and Confidentiality trust service criteria. Most recent audit window included.

    FORMATPDF · 86 pp AS OFQ4 2025 TURNAROUNDinstant
  2. 02

    Subprocessor list & locations

    Named list of every third-party processor that touches customer data, the data they receive, and the region in which it is stored.

    FORMATPDF · 4 pp COUNT9 listed TURNAROUNDinstant
  3. 03

    Data Processing Agreement (DPA)

    Pre-signed standard contractual clauses ready for counter-signature. Covers GDPR Art. 28 processor obligations and CCPA service-provider terms.

    FORMATPDF · 18 pp JURISDICTIONEU + US TURNAROUNDinstant
  4. 04

    Penetration-test summary

    Executive summary from our most recent third-party pentest. Findings, severity, and remediation status — no NDAs required for the redacted version.

    FORMATPDF · 12 pp AS OFQ4 2025 TURNAROUNDinstant
SECURITY-REVIEWER FAQ

Questions your security team will ask before signing.

The six that come up on every vendor-risk review. If we missed yours, write to [email protected] and a human on the security team responds within one business day.

Where does customer data physically reside?+

Primary region is AWS us-east-1 (Virginia). EU customers can opt into AWS eu-west-1 (Ireland) at provisioning. Backups stay in-region. We do not replicate across regions without a written instruction.

How is data encrypted, and who holds the keys?+

AES-256 at rest via AWS KMS. TLS 1.3 in transit, HSTS preload. Enterprise plans can bring customer-managed keys (CMK) backed by AWS KMS or HashiCorp Vault — rotation handled by you.

What is your breach-notification timeline?+

Confirmed security incidents affecting customer data are reported within 72 hours of confirmation, per GDPR Art. 33. Customers receive a written notice including scope, data categories affected, and remediation steps.

How are subprocessor changes communicated?+

Customers receive 30 days' written notice before any new subprocessor touches their data, via the email address on the security contact. The trust portal updates on the same day the change goes live.

Which employees can access customer data, and how?+

Access is granted on a documented least-privilege basis, requires MFA and SSO, and is revoked within 24 hours of role change. Production access is brokered through a bastion with full session recording. No standing access.

How is SOC 2 evidence collected and audited?+

Controls and evidence live in a single internal control map. An independent Big-4-adjacent auditor samples controls every quarter, with a full Type II report issued annually. The trust portal reflects control changes within 24 hours.

TRUST VALIDATED · NEXT STEP

Trust checks out. See the HUD on your data next.

Book 30 minutes with a solutions engineer. Connect one of your 47 supported sources — Stripe, Snowflake, HubSpot, Linear, Segment — and watch a leading indicator surface in under 14 minutes. No SDR follow-up loop.

We respond within one business day. No marketing list.