Legal & Trust Center

Security Policy

Last Updated: 17 August 2026

Security at HubNest

Security is a core part of the HubNest platform.

HubNest is designed around controlled access, authentication, data protection, monitoring, role-based permissions, secure integrations, and auditability.

1. Authentication

HubNest may support:

  • Email and password authentication;
  • Mobile OTP;
  • Two-factor authentication;
  • Device verification;
  • Session management;
  • Password reset;
  • Login activity tracking.

Certain administrative roles may require stronger authentication controls.

The Cloud Calling architecture, for example, defines email/password login, OTP, 2FA, device verification, session management and suspicious-login detection.

2. Role-Based Access Control

HubNest uses role-based access principles to restrict access to appropriate modules and information.

Permissions may include:

  • View;
  • Create;
  • Edit;
  • Delete;
  • Module access;
  • Feature-level access;
  • Administrative controls.

This approach helps ensure that users receive only the access required for their responsibilities.

3. Encryption

HubNest uses encryption to protect sensitive information during transmission and storage where applicable.

HubNest implements TLS 1.2/1.3 for data in transit and AES-256 for sensitive data at rest.

4. API and Integration Security

HubNest may provide APIs and integrations.

Security controls may include:

  • API authentication;
  • Token-based access;
  • API key management;
  • Webhook controls;
  • Secure credential storage;
  • Permission-based integration access.
The Cloud Calling admin architecture specifically includes API-key management, webhook configuration, token-based access and secure storage.

5. Session Security

HubNest may provide:

  • Session expiration;
  • Logout from all devices;
  • Device tracking;
  • Login history;
  • Suspicious-session detection.

6. Monitoring and Audit Logs

HubNest may maintain logs relating to:

  • Login activity;
  • User actions;
  • Administrative changes;
  • Security events;
  • System events;
  • API activity;
  • Access events.

Audit logs help investigate suspicious activity and maintain accountability.

The source security material specifically describes event, audit, administrator and operator logging and monitoring for unusual activity.

7. Vulnerability Management

HubNest may use:

  • Security scanning;
  • Dependency monitoring;
  • Code review;
  • Vulnerability assessment;
  • Penetration testing;
  • Security incident monitoring;
  • Remediation processes.
Only publish specific tools/certifications after they are actually implemented.

8. Infrastructure Security

HubNest's infrastructure may use appropriate controls such as:

  • Network access controls;
  • Firewalls;
  • Network segmentation;
  • Secure server configuration;
  • Intrusion detection;
  • Rate limiting;
  • DDoS protection;
  • Redundant infrastructure.
The supplied security reference describes these controls as part of its infrastructure-security model.

9. Backup and Disaster Recovery

HubNest may maintain backups and recovery mechanisms designed to:

  • Protect against data loss;
  • Support service restoration;
  • Recover from infrastructure failures;
  • Maintain business continuity.
Do not publish exact backup frequency or retention periods until HubNest's actual infrastructure has finalized them.

10. Employee and Administrative Access

Access to sensitive systems should follow:

  • Least-privilege principles;
  • Role-based permissions;
  • Strong authentication;
  • Controlled administrative access;
  • Activity logging;
  • Periodic review.
The supplied security reference specifically uses least privilege, role-based permissions, strong authentication and administrative logging as security controls.

11. Security Incident Response

If HubNest identifies a security incident affecting customer or personal information, HubNest will investigate and take reasonable steps to:

  1. Contain the incident;
  2. Assess its impact;
  3. Remediate the issue;
  4. Restore affected services where necessary;
  5. Provide notifications where required by applicable law or contractual obligations.

12. Security Reporting

If you discover a potential security vulnerability affecting HubNest, please report it to:

Security Contact: hubnestsupport@gmail.com

Please do not publicly disclose a vulnerability before HubNest has had a reasonable opportunity to investigate and address it.