Your documents are the business. We treat them that way.

Most of what follows is unglamorous and that is rather the point. Here is what protects your documents, in plain terms, with the parts we have not built called out as clearly as the parts we have.

Encrypted in transit and at rest

TLS 1.3 on the wire and AES-256 on disk, with keys held in a managed key service and rotated quarterly. Backups use the same keys and are restored into a test environment every month, because a backup nobody has restored is a guess.

Access that matches your org chart

Permissions attach to teams and document types rather than folders, so a bookkeeper sees invoices across every client and nothing else. Single sign-on and enforced two-factor come with Office.

An audit log you can read

Every action against a document is recorded with the person, the time and the address it came from. The log is append-only, searchable, and exports as CSV.

Data residency you choose

Pick Canada, the United States, the United Kingdom or Germany at setup. Your documents and their backups stay in that region and are not processed anywhere else.

Tested by people who are not us

SOC 2 Type II, renewed annually. Penetration testing twice a year by an outside firm, with the summary report available to customers on request.

Your documents are not training data

The models that classify and read your documents are not trained on your content, and nothing you store is used to improve a shared model.

If something goes wrong

We will tell you within 24 hours of confirming an incident that touches your data, before we have the full picture and before it is comfortable to do so. You will get what we know, what we do not yet know, and what we are doing about it.

Status and past incidents are public at status.infohive.app, including the ones nobody noticed. A status page that only shows good news is a marketing page.

What we have not done

Worth knowing before you commit, and easier to read here than to discover in month four.

  • No ISO 27001 certification. It is scheduled for next year, and we would rather say so than imply it.
  • No on-premise installation. InfoHive is hosted only, in the region you choose.
  • No customer-managed encryption keys yet. Keys are managed by us, rotated quarterly.
  • Single sign-on is on the Office plan only, which we know is annoying on Practice.

Send us the security questionnaire.

We answer them ourselves, usually within two working days, and we will tell you when the honest answer is no.