Loading...
Loading...
Independent audits, encryption in transit and at rest, separated access, and a release boundary your team controls.

An independent service auditor examined the design and operating effectiveness of the applicable controls over the review period, covering all Huscribe services. Available for review under NDA.

Certified information security management, assessed against the international standard by an accredited certification body.
You retain all ownership rights, title, and interest in your content. Huscribe does not claim ownership over it, and connecting a CRM does not change who owns what is inside it.
Project deliverables and usage rights for any workflow change are set out in the agreement, and the source, tests, documentation and deployment manifest are delivered into a repository you control.
Ownership terms: section 4.1 of the Terms of ServiceTLS 1.3 in transit and AES-256 at rest. That covers the conversations your team captures on the way to Huscribe and the structured records Huscribe holds.
Your storage region is agreed at onboarding, so your review team knows where the data sits before anyone connects an account.
Retention and deletion controls are documented, and the published retention and deletion policy sets the windows that apply to your workspace.
When an account is deleted, the deletion propagates across active application data stores in line with that policy. The policy itself is part of the documentation pack your review team receives.
Retention and deletion policy available during security reviewWhen we prepare a workflow change, production discovery uses a dedicated identity you approve, through a service restricted to retrieval and scoped to the workflow we agreed. It reads. It changes nothing.
Building and testing happen on a separate sandbox connection, so the work never shares an identity with your live system.
We do not deploy to production. Your authorised release team decides whether and when a change goes live, through your own release process and tooling.
That boundary does not move, and it sits in the agreement rather than only on this page.
You can edit or reject proposed CRM updates before they are committed, on every capture route except meeting notes, which are written automatically and can be undone afterwards.
Extracted information carries its source and date, and inferences are labelled rather than presented as sourced facts, so a reviewer can see where anything came from.
Requirements, approvals, tests, versions and release evidence are recorded and available to you. Every item traces back to the requirement you approved.
Admin-controlled invitations and access, manager visibility aligned to the team structure, Microsoft and Google sign-in, and supported connections managed from one workspace.
DPA, subprocessor list, retention, and deletion details, available during security review, alongside the SOC 2 Type II report under NDA and the ISO/IEC 27001:2022 certificate.
Yes. The SOC 2 Type II report covers all Huscribe services and is available for review under NDA. Ask your Huscribe contact, or email support@huscribe.com.
The storage region is agreed at onboarding.
Production discovery uses a dedicated identity you approve, through a service restricted to retrieval, scoped to the workflow we agreed. Build and testing use a separate sandbox connection.
No. We build and verify outside production. Your authorised release team decides whether and when a change goes live. That boundary does not move.
Usually the SOC 2 report, the ISO/IEC 27001:2022 certificate, the DPA and the subprocessor list. All of it is available during security review.
DPA, subprocessor list, retention and deletion details, and the reports themselves, available during security review.
Ask us for the documents