Security and data location
Where your data is stored, how it is protected, and who processes it
Last updated: 09/25/2026
This page says where Hub Nexus keeps your data, how it is protected, and which companies process it for us. It covers the public site and private workspaces alike.
Where your data is stored
- Everything you write, upload or set up on Hub Nexus — pages and every version of them, comments, workspaces, their members and settings — is stored in Amazon Web Services' US West (Oregon) region, us-west-2, in the United States.
- The application that serves it runs in the same region.
- We do not copy your data to other regions, and we do not yet offer hosting in another region.
How it reaches readers
- Pictures and video are delivered through Amazon CloudFront, which keeps short-lived copies at locations near readers around the world. Files are only served through signed links that expire.
- Search over public pages is built from public pages only. A private workspace's pages are never part of it.
How it is protected
- Your data is encrypted in transit (HTTPS) and at rest (AES-256).
- The database can be restored to any moment in the last 35 days, and earlier versions of files are kept for 30 days.
- Access to the production systems is limited to the people who operate the service, through their own AWS roles.
- Workspaces keep an audit log of who did what, which their administrators can export. Organisations can connect their own sign-in (SAML or OpenID Connect) and provisioning (SCIM), and can require approvals to be signed.
Companies that process data for us
These companies process data on our behalf. Each is bound by its own security and privacy commitments.
- Amazon Web Services, Inc. — hosting, storage, content delivery and sending email (United States).
- Stripe, Inc. — payments. Card details go to Stripe and never reach our servers (United States).
- Google LLC, through Google Workspace — our own email, including messages you send to our addresses (United States).
Compliance
We keep a readiness pack for SOC 2 — our policies, a map of our controls and the evidence behind them — and share it with organisations evaluating Hub Nexus. Hub Nexus has not yet been audited against SOC 2 or ISO 27001.
Reporting a security problem
If you find a security problem, write to support@hubnx.com. Please give us a chance to fix it before telling anyone else, and do not access data that is not yours.