Skip to content
NotifyHub.ai

Trust

Built for organizations that depend on their data.

This page describes how the platform is built. Where a formal certification is not held, it is not claimed.

Practices

How the platform handles access and data.

Access control

Roles carry permission codes that determine which records and operations a person can reach. Access is defined per organization, not globally.

Authentication

Sign-in, session handling, and credential management are part of the platform rather than each product.

Authorization

Permission checks are applied in the application and data layers, so hiding a control in the interface is never the only barrier.

Tenant isolation

Every record belongs to a tenant, and tenant scope is the primary isolation boundary throughout the platform.

Audit trails

Significant system activity is recorded so that it can be reviewed afterwards.

Data protection

Data is transmitted over encrypted connections and stored in managed infrastructure.

Backups

Operational data is backed up as part of platform operations.

Reliability

Services are designed to degrade predictably and to recover without losing operational records.

Responsible AI architecture

Calculations that can be deterministic are computed deterministically. AI explains findings and proposes actions within the permissions of the person viewing them.

On certifications

NotifyHub does not currently claim SOC 2, ISO, HIPAA, or any other formal certification, and does not use phrases like “bank-grade” or “military-grade” security. If your organization requires a specific attestation, contact us at [email protected] and we will tell you plainly where we stand.