Security

Built for the review your compliance team runs.

What we're certified for, what we never do with your data, and what we'll sign.

SOC 2 Type IISOC 1 Type IISOX-alignedHIPAA-readyGDPR
01

Certifications

Independent auditors test our controls every year.

SOC 2 Type II

Security, availability and confidentiality controls across every system.

SOC 1 Type II

Controls over financial reporting, examined by a licensed CPA firm.

HIPAA-ready

Deployable under a BAA when protected health information is in scope.

Penetration testing

Third-party tests at least annually, with results shared under NDA.

02

Your data

Encrypted, isolated, and never used for anything but your work.

Encryption

AES-256 at rest and TLS 1.3 in transit, everywhere.

No model training

Your ledger is never used to train models, ours or anyone else's.

Tenant isolation

Each customer's data is logically separated with its own keys.

Retention you control

Set retention periods and request deletion at any time.

03

Access and controls

The same controls your auditor expects from your own team.

Least privilege

Read-only by default. Write access is scoped per system and workflow.

Segregation of duties

Metahubs prepares. Named people on your team approve.

SSO and SAML

Sign in through Okta, Google or Microsoft Entra ID.

Full audit trail

Every action logged with source, preparer, reviewer and timestamp.

04

What we'll sign

Standard agreements ready for your legal team.

DPA

Data processing agreement aligned with GDPR and CCPA.

BAA

Business associate agreement for HIPAA-covered data.

MSA

Master services agreement with security exhibit.

Custom terms

Enterprise plans can negotiate additional security terms.

Trust Center

Documents for your review

Available under NDA. Most requests are answered the same day.

SOC 2 Type II reportMost recent audit period
Request →
SOC 1 Type II reportControls over financial reporting
Request →
Penetration test summaryThird-party, annual
Request →
Subprocessor listUpdated quarterly
Request →
Data processing agreementGDPR and CCPA
Request →
Security questionnaireSIG Lite and CAIQ
Request →

FAQ

Security questions

Sending a questionnaire? We'll complete it.

Where possible we connect with OAuth or API tokens. Any stored secrets are encrypted in a managed vault and never visible to staff.

Put Metahubs on your first workflow.

Walk us through how your team closes today. We'll show the same work running in your tools.

Book a Demo →