Information security at ArchiveHub.
Protecting the confidentiality, integrity and availability of enterprise information is central to our security policy. Explore how our policy addresses access, data protection, operational security and the people who handle your information.
A documented security policy.
Our Information Security Policy applies to ArchiveHub employees, contractors, partners and third-party service providers, and to systems, applications, networks and cloud infrastructure managed or hosted by ArchiveHub. It covers customer data, metadata, personal information, business-process data and archived records.
The policy assigns oversight and risk-assessment responsibilities to an Information Security Officer, technical-control responsibilities to system administrators, and security obligations to personnel and vendors. It requires review annually and following significant changes in technology, threats or regulatory requirements.
What our policy requires.
These requirements summarize our corporate security policy. Customer-specific controls and supporting evidence can be discussed during a security review.
Least privilege and authentication
Access is governed by least privilege and role-based authorization at the system, data and application levels. The policy requires multi-factor authentication for administrative access and remote logins, and timely removal of access when personnel leave.
Encryption and separation
The policy requires encryption of sensitive data at rest and in transit, using TLS 1.2 or later for transport. It also requires encrypted backups in redundant zones and logical separation of customer data in multi-tenant environments.
Infrastructure and endpoint security
Requirements include firewalls, intrusion detection, network segmentation, regular vulnerability scans and patch management. Company-managed devices require endpoint protection and disk encryption, with controls on removable storage.
Reporting and response procedures
The policy requires prompt internal reporting of security incidents and a regularly tested incident response plan. Affected customers are notified in accordance with applicable regulatory requirements.
Security awareness and training
Employees are required to complete annual security awareness training. New joiners receive security and privacy briefings, and the policy includes regular phishing simulations.
Third-party security
Vendor requirements include security due diligence and data processing agreements. The policy also requires isolation and monitoring of third-party integrations and physical protection for hosting environments.
Retention and secure disposal
Information must be retained according to applicable contractual and legal obligations. Secure deletion or destruction is required when the applicable retention period expires and disposal is authorized.
Legal and customer obligations
The policy addresses applicable privacy obligations, including Canadian privacy requirements, and customer contractual requirements. Our Privacy Statement explains how website inquiries and personal information are handled.
Security in your deployment.
ArchiveHub supports enterprise identity and single sign-on, granular authorization, encryption, audit and information-lifecycle capabilities within appropriately configured deployments. Configured retention and legal-hold processes help govern preserved historical information.
The hosting model, identity provider, connected systems and customer configuration determine how controls are implemented and who operates them. Applicable responsibilities and service commitments are defined by the deployment architecture and customer agreement. See the Trust Center for more on shared responsibility and historical-data governance.
For customer security reviews.
Which URL can I use in a supplier questionnaire?
Use https://archivehub.io/security/ as ArchiveHub's public information security page. It provides a summary of the security policy and a route to request supporting documentation.
Can I request the full Information Security Policy?
Yes. Contact [email protected] with your organization and review requirements. The full policy and relevant supporting documentation can be requested through our customer security-review process.
Does this page establish an ISO 27001 certification or SOC 2 report?
No. Policy references to security standards are distinct from an independent certification or assurance report. Any certification or audit evidence relevant to your evaluation should be requested and checked for its entity, scope and validity.
How are deployment-specific requirements handled?
During the customer review, we can discuss hosting, identity and access, data protection, backup and recovery, retention and operational responsibilities for the proposed environment. The applicable architecture and agreement establish the commitments for that deployment.
Security documentation
For supplier questionnaires and customer due diligence, share the documents or control areas you need to review.
Contact [email protected]Report a security concern
Send the affected component, a brief description and your contact details. Keep credentials and customer records out of the initial email.
Contact [email protected]This public overview summarizes Information Security Policy AH-SEC-01, version 4.0. It is not an audit report or a contractual security schedule. Supporting evidence and customer-specific commitments are addressed through the security-review process and applicable agreements.
Assess an Application