Skip to main content
< All Topics
Print

Understanding Our Encryption and Security Standards

SaaSi Hub uses a combination of encryption, secure authentication methods, controlled access and protected infrastructure to help keep customer data secure.

Security is not treated as a one-time implementation. We regularly review our security practices, apply updates and monitor our infrastructure to maintain our security posture as standards and risks evolve.

Encryption in Transit

All connections to the SaaSi Hub platform take place over secure connections.

Data transferred between your browser, connected SaaS applications and SaaSi Hub’s internal platform servers is encrypted using TLS 1.2 or higher. This helps protect information while it is being transmitted and reduces the risk of data being intercepted during transfer.

Encryption at Rest

Data stored within SaaSi Hub’s databases and backups is protected using AES-256 encryption. This provides encryption for database volumes and backups while information is stored within the platform.

Secure SaaS Authentication

SaaSi Hub uses OAuth 2.0 for SaaS integrations wherever it is available, including supported integrations such as Google Workspace and Slack. OAuth allows SaaSi Hub to request authorised access to the information required from a connected application without requiring SaaSi Hub to store your SaaS account password.

Where an integration uses manual authentication instead, SaaSi Hub states that it does not see or store your passwords.

Minimum Required Permissions

When connecting SaaS applications, SaaSi Hub requests only the permissions required to identify relevant licence usage and user status and display that information within your SaaSi Hub dashboard and reports.

This approach helps limit the information and access requested from connected applications to what is required for the integration’s intended purpose.

You can also revoke SaaSi Hub’s access directly through the administration console of the relevant SaaS provider.

Secure Hosting Infrastructure

SaaSi Hub’s internal platform is hosted on Google Cloud, using its physical and network security infrastructure.

The public-facing SaaSi Hub website is hosted with an ISO 27001-certified secure server provider and uses DDoS protection, SSL encryption and real-time security scanning.

Data Residency

Customer data within the SaaSi Hub internal platform is processed and stored across US-East and EU-West regions. For more information about where customer data is stored and processed, see where is customer data stored?

Payment Security

SaaSi Hub does not store your debit or credit card information.
Payments are processed through Stripe, which is a PCI-DSS Service Provider Level 1 payment processor. SaaSi Hub does not see or store card information when you use the online billing system.

For more information, see secure payment processing and billing protection.

Our Approach to Security

Security involves more than a single encryption standard or technology. SaaSi Hub combines encrypted connections, encrypted storage, controlled authentication, limited integration permissions and secure hosting infrastructure to protect information throughout its lifecycle.

We also regularly review our security practices and infrastructure so that security measures can evolve alongside changing technology and emerging risks.

In short, SaaSi Hub uses encryption both when data is being transferred and when it is stored, while secure authentication and controlled permissions help limit access to connected systems.

Table of Contents