Encryption
Everything is encrypted in transit with TLS 1.3 and at rest with AES-256. Backups are encrypted with the same standard and are restored and tested every quarter.
Access control
Workspaces support role based permissions, single sign-on and two factor authentication. Internally, access to production is limited to the engineers who need it, granted for a fixed window and logged.
Infrastructure
Cloudhub runs on providers certified to ISO 27001 and SOC 2 Type II. Environments are isolated, and infrastructure changes go through peer review before they ship.
Monitoring
Availability, errors and unusual sign-in patterns are monitored around the clock. On-call engineers are paged automatically when a threshold is crossed.
Testing
Independent penetration tests run annually and after any significant architecture change. Dependencies are scanned daily and patched on a fixed schedule based on severity.
Incident response
We have a written incident response plan with named owners. Customers affected by a confirmed breach are notified within seventy-two hours, with what happened, what data was involved and what we did about it.
Your part
Turn on two factor authentication, review who has access to your workspace every quarter, and remove people when they leave.
Reporting a vulnerability
Send anything you find to hi@cloudhub.com. We acknowledge reports within one working day and we will not pursue legal action against good faith research.