Last reviewed August 19, 2026

Security And Trust

Engineer Hub separates the public evaluation site from the protected operations application, limits access by role and organization, and retains security and audit evidence. This page distinguishes implemented controls from independent assurance that is still in progress.

Current delivery controls

Encrypted delivery

Engineer Hub uses HTTPS through Cloudflare. HSTS is configured across the Engineer Hub domain to keep supported browsers on encrypted connections.

Protected operations

The public app route does not expose the operator application bundle. The operator console is isolated on ops.theengineerhubapp.com behind Cloudflare Access and application authentication.

Scoped access

Server-side sessions, login throttling, role permissions, and organization and building scope are used to restrict operational records and administrative actions.

Traceable changes

Important actions are recorded in an audit trail. Audit exports include hash-chain evidence so later changes can be detected.

Enterprise browser access

Corporate web filters may require an explicit allowlist even when TLS is valid. An IT administrator can allow the following destinations over HTTPS:

Engineer Hub does not require browser extensions or inbound firewall rules. Customer-specific identity-provider domains may also be required when enterprise SSO is activated.

Independent assurance status

Independent penetration testPlanned; no external report has been issued.
CSA STAR Level 1Evidence preparation; not submitted.
SOC 2Readiness roadmap established; no CPA examination report has been issued.
ISO/IEC 27001:2022ISMS roadmap established; no accredited certificate has been issued.

Engineer Hub does not claim certification, attestation, or independent testing until the responsible external authority issues evidence for a defined scope and period.

Responsible disclosure

Report a suspected vulnerability to [email protected]. Include the affected URL, a concise description, reproduction steps, and the potential impact. Do not access another organization's data, disrupt service, use social engineering, or publish sensitive details before Engineer Hub has had a reasonable opportunity to investigate.

Automated systems can read our security.txt. Privacy information is available in the Privacy Notice.