Security in the product
Hubyfy uses authenticated sessions and workspace permissions to control access. Supported safeguards include optional multifactor authentication, role-based access, protected private-file downloads and encrypted storage of connected-account credentials. Administrators must configure memberships and integrations appropriately. Spaces has its own access controls and must be assessed for its selected deployment.
Production transport, hosting, backup, monitoring and recovery controls depend on the deployed environment. The planned AWS deployment separates application containers, private database access and private object storage, with runtime secrets outside application images. These are deployment requirements, not evidence that a live environment has already passed a security audit.
Your responsibilities
Protect account credentials, enable available multifactor authentication, use the minimum necessary permissions and review shared links and connected services. Obtain permission before recording or processing another person’s information. Report suspected unauthorized access promptly.
Report a vulnerability
Email hubyfy99@gmail.com with “Security report” in the subject. Include the affected product, route, impact and minimal steps to reproduce using your own test account. Redact secrets and personal data. Ask for a suitable secure channel if sensitive evidence is needed.
Do not access another customer’s data, run denial-of-service tests, use social engineering, or continue exploiting a finding. This reporting channel does not grant permission to test systems or promise a bounty. We assess reports, coordinate remediation and communicate as appropriate to the issue.
Incidents and assurance
We investigate suspected incidents, contain affected access, preserve relevant evidence and notify affected customers or authorities where required by the applicable agreement and law. Ask support for the safeguards and contractual commitments that apply to your deployment. We do not claim SOC 2, ISO 27001 certification, guaranteed uptime, end-to-end encryption or a completed independent audit without specific supporting evidence.
Need help?
Contact hubyfy99@gmail.com. Include the product and relevant organization, but never send passwords, access tokens or payment-card details.
