🛡️
Trust Center

Built to read your org — not to hold it.

Hubbl was designed from day one to give you deep visibility without deep access. Credential-free scanning, least-privilege by default, and independently audited controls — so security teams can say yes in minutes, not months.

SOC 2 Type II · HIPAA · ISO 27001 · nothing stored by default
SOC 2Type II
SOC 2Type I
HIPAACompliant
ISO 27001Certified
GDPRCompliant
CCPACompliant
How Hubbl handles your data

Deep visibility, without deep access.

Most tools that understand your org need broad, standing access to it. Hubbl doesn't. The scan reads metadata to build its picture, runs with least privilege, and stores nothing by default — so the thing that makes Hubbl safe to run on any org is the same thing that makes it powerful.

  • No credentials handoff — connect without giving up admin credentials.
  • Read-only, least privilege — Hubbl sees what it needs and nothing more.
  • Nothing stored by default — your org data isn't retained after a scan.
  • Your data is never used to train models.
Diagram — credential-free scan: read metadata → analyze → nothing retained
Our security program

Security built into every layer.

🔒

Data protection

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • No customer org data retained after a scan by default
  • Strict data-segregation between customers
  • Documented retention & deletion policies
👤

Access & authentication

  • SSO & SAML, plus Google and Salesforce login
  • Role-based access control and least privilege
  • MFA enforced for all Hubbl personnel
  • Scoped, revocable connections — no standing admin access
🏛️

Infrastructure

  • Hosted on SOC 2–certified cloud infrastructure
  • Network isolation, WAF, and continuous monitoring
  • Automated vulnerability scanning & patching
  • Audit logging across the platform
📋

Compliance & privacy

  • SOC 2 Type II, ISO 27001, HIPAA
  • GDPR & CCPA aligned; DPA available
  • Documented subprocessor list
  • Annual third-party penetration testing
🤖

AI & LLM data handling

  • Your org data is never used to train models
  • The Hubbl MCP passes context, it doesn't hand over your org
  • Enterprise AI providers under contractual no-train terms
  • You control what's shared with connected agents
🔁

Reliability & resilience

  • Documented business continuity & DR plans
  • Regular encrypted backups
  • Uptime monitoring and status transparency
  • Incident response plan with defined SLAs
The specifics

What Hubbl accesses — and what it doesn't.

What Hubbl reads
Org metadata — objects, fields, flows, automations, packages, profiles, and permission sets — to build the inventory and health picture.
What Hubbl doesn't touch
Your customer records / row-level data. The scan is built on metadata, not the contents of your database.
How it connects
A scoped, least-privilege connection — no credentials handoff, no standing admin access. Revoke anytime.
What's retained
Nothing by default. Results you choose to save stay in your workspace under your control; org data isn't retained after a scan otherwise.
Model training
Your data is never used to train AI models — Hubbl's or a third party's.
Data residency
Placeholder — confirm region options (US / EU) with security before publish.

Security documentation

Access our SOC 2 report, penetration test summary, security whitepaper, and DPA through the Hubbl trust portal — under NDA where required.

Request access →

Report a vulnerability

Found something? Our responsible disclosure program is the fastest way to reach the security team. We investigate every report.

security@hubbl.com →
Common questions

Security FAQ.

Do you need admin credentials to run a scan?

No. Hubbl connects with a scoped, least-privilege connection and never requires you to hand over admin credentials. That's why the scan is safe to run on any org — including a prospect's.

Is my org data stored?

Not by default. Hubbl reads metadata to produce your picture and retains nothing after the scan unless you choose to save results into your workspace.

Is my data used to train AI models?

Never. Your org data is not used to train Hubbl's models or any third-party model, and enterprise AI providers operate under contractual no-train terms.

Can I get your SOC 2 report and a DPA?

Yes — request access through the trust portal above. Reports are available under NDA where required, and a DPA is available for customers.

How does the Hubbl MCP handle data with agents like Claude?

The MCP passes org context to the agent you connect — it doesn't hand over your org. You control what's shared, and no data is retained for training.

Safe enough to run on any org.

See exactly what Hubbl sees — a credential-free scan in about two minutes, with nothing stored. Security teams welcome.