Engineer Hub uses HTTPS through Cloudflare. HSTS is configured across the Engineer Hub domain to keep supported browsers on encrypted connections.
Last reviewed August 19, 2026
Security And Trust
Engineer Hub separates the public evaluation site from the protected operations application, limits access by role and organization, and retains security and audit evidence. This page distinguishes implemented controls from independent assurance that is still in progress.
Current delivery controls
The public app route does not expose the operator application bundle. The operator console is isolated on ops.theengineerhubapp.com behind Cloudflare Access and application authentication.
Server-side sessions, login throttling, role permissions, and organization and building scope are used to restrict operational records and administrative actions.
Important actions are recorded in an audit trail. Audit exports include hash-chain evidence so later changes can be detected.
Enterprise browser access
Corporate web filters may require an explicit allowlist even when TLS is valid. An IT administrator can allow the following destinations over HTTPS:
theengineerhubapp.comandwww.theengineerhubapp.comfor public information and evaluation.ops.theengineerhubapp.comfor the protected operations application.*.cloudflareaccess.comfor the Cloudflare Access sign-in flow.static.cloudflareinsights.comandcloudflareinsights.comfor optional site-performance analytics. Blocking analytics does not block core application use.
Engineer Hub does not require browser extensions or inbound firewall rules. Customer-specific identity-provider domains may also be required when enterprise SSO is activated.
Independent assurance status
Engineer Hub does not claim certification, attestation, or independent testing until the responsible external authority issues evidence for a defined scope and period.
Responsible disclosure
Report a suspected vulnerability to [email protected]. Include the affected URL, a concise description, reproduction steps, and the potential impact. Do not access another organization's data, disrupt service, use social engineering, or publish sensitive details before Engineer Hub has had a reasonable opportunity to investigate.
Automated systems can read our security.txt. Privacy information is available in the Privacy Notice.