Transparent reporting on our current security implementation and roadmap toward enterprise-grade compliance.
Hubeu is an early-stage European hosting platform building security and compliance incrementally. This page provides honest disclosure of our current capabilities, ongoing work, and future plans. We believe transparency builds trust with our community.
Security measures we have deployed and operational in production today.
Core infrastructure hosted on Hetzner (Germany) and Scaleway (France). User deployments stay within EU borders.
JWT-based authentication with Supabase. Role-based access in development.
TLS 1.2+ for all web traffic. API endpoints and user applications secured with SSL certificates.
Database backups via Supabase. Application data backed up regularly to prevent loss.
Security features currently being implemented and tested.
Implementing stunnel for encrypted Redis communication between regions. Currently testing configuration.
Adding seccomp profiles, resource limits, and enhanced Docker security controls for user deployments.
Building comprehensive logging for user actions, deployments, and system access for security monitoring.
Finalizing DPAs with infrastructure providers (Hetzner, Scaleway, BunnyCDN) for GDPR compliance.
Formal certifications and regulations we're planning to implement as we scale.
Right to be forgotten, data portability, breach notification system, and complete privacy controls.
Formal Information Security Management System (ISMS) certification. Requires 18-24 month implementation.
Independent security audit certification. Requires 12+ months of documented controls before audit.
Technical security measures currently protecting your applications and data.
Transparency about our current limitations and ongoing development status.
Hubeu is in active development with evolving security features
Full regulatory compliance is planned but not yet achieved
As a startup, we prioritize security features based on available resources
Access our policies and agreements (updated as features are implemented).
We're committed to building security and compliance transparently. Our roadmap evolves based on user needs and industry standards.