Hubseat Cloud

Security

Last updated: June 1, 2026

1. Security overview

Hubseat Cloud is designed for teams that run production workloads. Security is a shared responsibility: we secure the platform we operate; you secure your configurations, credentials, application code, and data classifications.

2. Platform isolation

Customer environments are logically separated by workspace and project boundaries. Managed engines run on infrastructure operated by Hubseat with network controls intended to prevent cross-tenant access. Misconfiguration (public endpoints, weak passwords, over-privileged roles) can still expose data — that risk sits with the Customer.

3. Identity and access

Authentication is provided through Authsense with support for organization-managed policies. Authorization in the console follows role-based access scoped to workspaces and projects. We recommend MFA for all human users and rotation of API tokens used in CI/CD.

4. Encryption and secrets

Transport to supported console and API endpoints uses TLS. Secrets and connection credentials are stored with access controls and are not displayed in plain text after creation. You are responsible for not committing secrets to source control or sharing them informally.

5. Managed services operations

Managed PostgreSQL, MariaDB, Redis, and other engines receive patching and operational monitoring according to platform standards. Backups and point-in-time recovery depend on your plan — verify retention settings for each environment.

6. Hubseat Desktop secure access

Hubseat Desktop opens authenticated local TCP tunnels to service containers without exposing databases on the public internet. Sessions are tied to your Hubseat identity and respect the same RBAC boundaries as the console.

7. Monitoring and incidents

We monitor platform health and investigate alerts affecting availability or integrity. When an incident materially impacts Customer Data or Service availability, we notify affected customers according to contractual commitments and applicable law, describing known impact and recommended mitigations.

8. Vulnerability reporting

If you believe you have found a security vulnerability, report it responsibly through our contact channels. Please avoid public disclosure until we have had reasonable time to investigate and remediate.