Public trust portal
A live, versioned page listing every control in scope, its current owner, and when it was last reviewed. No login wall.
HBHUD is built for leadership teams who can't guess on data stewardship. Our trust posture is the same as our product posture — observable, auditable, and updated the moment something changes. No email tag required.
Marketing claims don't pass vendor risk review. We publish the four artifacts a reviewer pulls during diligence — live, with timestamps, no NDA gate.
A live, versioned page listing every control in scope, its current owner, and when it was last reviewed. No login wall.
When a control is added, retired, or moved between owners, the trust portal reflects it within 24 hours. Verified by an internal CI check.
Every third party that touches customer data, named with region and purpose. Customers are notified 30 days before any addition.
Past security incidents are published with timeline, root cause, and customer impact — even the boring ones. Zero since platform GA.
The exact artifacts a VP Product or a PE operator pulls during vendor review. Each one is current as of the timestamp printed on the cover page.
Full Type II report covering the Security, Availability, and Confidentiality trust service criteria. Most recent audit window included.
Named list of every third-party processor that touches customer data, the data they receive, and the region in which it is stored.
Pre-signed standard contractual clauses ready for counter-signature. Covers GDPR Art. 28 processor obligations and CCPA service-provider terms.
Executive summary from our most recent third-party pentest. Findings, severity, and remediation status — no NDAs required for the redacted version.
The six that come up on every vendor-risk review. If we missed yours, write to [email protected] and a human on the security team responds within one business day.
Primary region is AWS us-east-1 (Virginia). EU customers can opt into AWS eu-west-1 (Ireland) at provisioning. Backups stay in-region. We do not replicate across regions without a written instruction.
AES-256 at rest via AWS KMS. TLS 1.3 in transit, HSTS preload. Enterprise plans can bring customer-managed keys (CMK) backed by AWS KMS or HashiCorp Vault — rotation handled by you.
Confirmed security incidents affecting customer data are reported within 72 hours of confirmation, per GDPR Art. 33. Customers receive a written notice including scope, data categories affected, and remediation steps.
Customers receive 30 days' written notice before any new subprocessor touches their data, via the email address on the security contact. The trust portal updates on the same day the change goes live.
Access is granted on a documented least-privilege basis, requires MFA and SSO, and is revoked within 24 hours of role change. Production access is brokered through a bastion with full session recording. No standing access.
Controls and evidence live in a single internal control map. An independent Big-4-adjacent auditor samples controls every quarter, with a full Type II report issued annually. The trust portal reflects control changes within 24 hours.
Book 30 minutes with a solutions engineer. Connect one of your 47 supported sources — Stripe, Snowflake, HubSpot, Linear, Segment — and watch a leading indicator surface in under 14 minutes. No SDR follow-up loop.