Security at Compliance Hub
Compliance Hub is designed to keep employer records within the account that owns them and to keep uploaded files out of the public marketing site. This page describes controls that are present in the product today without making claims about certifications or guarantees.
Employer account isolation
Operational records are associated with an employer account. Application workflows use the authenticated user's active employer context and check that context before returning employer documents and other records.
Private upload storage
Documents, certification files, and support attachments use employer-specific paths in private upload storage. Upload requests mark those files as non-public.
Authenticated file access
Document downloads go through authenticated file access in the application. Before returning a document, the application checks that it belongs to the current employer account. Depending on the configured storage mode, an authorized download is either streamed by the application or provided through a time-limited storage URL.
Subscription payments
Compliance Hub uses Stripe for subscription payment processing. The signup flow uses Stripe's payment components for card details, and the application stores Stripe customer and subscription references for account billing workflows.
Responsible use
No system can remove every security risk. Account owners should use unique passwords, limit account access to people who need it, and contact support if they believe an account or record has been accessed unexpectedly.