UHUBS POLICY

Application & Interface Security Policy

Last reviewed on 5 August 2026
Uhubs's Application & Interface Security Policy emphasizes the importance of technical infrastructure, secure partnerships, encryption of data in transit and at rest, software development lifecycle process, testing and monitoring, deployment process, technical and operational metrics, and manual testing strategy to ensure a secure and efficient technical environment.

1. Technical Infrastructure

1.1 Gold-Standard Partners

Third-party providers must meet Uhubs's 'gold-standard' criteria, ensuring that internal tools and solutions align with Uhubs's stringent security and data governance thresholds.

1.2 Shared Infrastructure

Uhubs's technical infrastructure combines in-house systems with third-party services. Where we outsource, we use established providers: Google Cloud Platform for compute and analytics, Supabase for the managed Postgres database, Vercel for web hosting, and GitHub for source control and deployment.

1.3 Sign-off for New Partners

The DPO and CTO must be consulted before any new third-party providers are added to Uhubs’s infrastructure.

2. Encryption

2.1 Data in Transit

All traffic between users and the Platform, and between the Platform and its integrations, is encrypted using TLS 1.2 or higher.

2.2 Data at Rest

Customer data is encrypted at rest using AES-256. This covers the primary database, file storage, and backups. Encryption keys are managed by our infrastructure providers through their platform key management tooling. Uhubs does not use hardware security modules and does not offer customer-managed encryption keys.

3. Uhubs Software Development Lifecycle Process

3.1 Release Cycle

Uhubs follows a well-defined Agile Software Development Life Cycle (SDLC) process with bi-monthly releases. Each release undergoes thorough testing, both automated and manual, prior to deployment.

3.2 Continuous Improvement

The tech team recommends infrastructure and security improvements monthly, prioritising enhancements based on business objectives and risk assessments.

4. Testing and Monitoring

4.1 Testing Procedures

Each new release undergoes multiple rounds of testing conducted by QA Engineers. Automated tests are built where possible, and smoke tests are run weekly to ensure baseline functionality.

4.2 Metrics and Monitoring

Key metrics are closely monitored on a daily basis, ensuring that any deviations from expected performance are swiftly addressed. An Application Performance Monitoring (APM) system alerts the team to potential problems.

5. Deployment Process

5.1 Secure and Efficient Deployment

Uhubs has invested in a secure and efficient deployment process, utilising leading tools like GitHub. This allows rapid deployment of new releases and patches to our microservices architecture.

5.2 Build Time and Success Rate

The team closely monitors build times and success rates, ensuring efficiency and reliability in the deployment process.

6. Technical and Operational Metrics

6.1 Metric Definition

Uhubs defines and implements technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.

6.2 Regular Evaluation

Metrics are regularly evaluated to ensure they remain relevant and effective in addressing evolving business needs and security challenges.

7. Manual Testing Strategy

7.1 Incorporating Manual Testing

A comprehensive manual testing strategy is integral to our Software Delivery Lifecycle (SDLC). Manual testing complements automated testing, focusing on areas where human intuition and exploration are crucial.

7.2 Scope and Depth

Manual testing encompasses a thorough evaluation of user interfaces, user experience, and scenario-based testing to ensure the robustness and security of our applications.

This Application & Interface Security Policy underscores Uhubs's commitment to a secure, efficient, and continuously improving technical environment.

8. Regular Policy Review and Updates

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.