HiveRoomby AVA Hive

Security and assurance

Control the room.
Understand the evidence.

A confidential transaction needs clear access rules, protected documents and an inspectable record of what happened. This overview explains HiveRoom’s deployed safeguards and the scope your security team should assess.

01

Workspace boundaries

Workspace membership and delegated operator grants determine administrative access. Room grants, participant status, groups and folder/file rules determine which documents a participant can view. Sensitive routes check the current authorization and scope their records to the workspace.

02

Authentication and MFA

Human accounts use password authentication with login throttling, optional or workspace-required MFA, recovery codes and verified passkeys. Account and access revocation invalidate subsequent authenticated requests. Delegated partner access uses expiring grants with separate credential boundaries.

03

Document viewing and downloads

Protected PDF viewing applies identity watermarks and authorization checks. Download permission is evaluated separately from viewing permission. Room, group and individual restrictions are enforced on the server before a PDF download is issued.

04

Cryptographic scope

Uploaded document objects use AES-256-GCM envelope encryption with a separate data key for each object. Selected profile and identity fields use application-level authenticated encryption. Browser connections use HTTPS. Internal PostgreSQL connections and document-service HTTP do not provide end-to-end TLS in the observed deployment. Database-volume, metadata, cache and internal-transport encryption require their own deployment qualification.

05

Upload and conversion controls

Uploads are checked for allowed format, size and file signatures and pass the configured malware scanner. The deployed scanner gate refuses unverified files. Office/PDF conversion and OCR run in an isolated processor with request authentication, bounded resources, temporary files and sandbox restrictions.

06

Audit and administration

Authentication, document, access and administrative workflows record audit evidence. Transactional controls protect the required evidence for covered critical mutations; the technical dossier explains the scope and limits. Actor and workspace context are recorded; Audit-entry IP evidence uses a keyed hash. Privileged workspace actions and delegated partner operations remain distinct. Audit export is available to authorized roles.

07

Committee reviews and buyer teams

Independent reviewers approve the exact submitted source through configured stages. Changed source content invalidates its earlier review. Buyer-team questions require owner activation and participant consent; membership and room access are checked again. Reminder emails require both workspace and recipient opt-in.

08

Scheduled reporting

Authorized teams can request encrypted audit and operations exports and configure UTC schedules. Access is checked before generation and again before download. Jobs have bounded retries and artifact expiration; reports disclose their record, date-range and format limits.

09

Storage and document retention

The current deployment uses encrypted local storage. Optional S3 and Azure Blob adapters transfer encrypted envelopes and retain a required encrypted local cache; provider activation needs an approved account and deployment qualification. Closed-room retention can match saved country and exact document categories and use document age or recorded room closure. Preservation holds block deletion. Agreements, audit records, backups and historical cloud versions follow separate retention.

10

API and webhook controls

Human workspace owners can manage scoped API credentials and opt-in metadata webhooks. Outbound destinations require verified public HTTPS routing, signed payloads and bounded durable retries. Demos cannot enable external integrations. Dedicated institution-specific connectors and recipient inbox delivery require their own qualification.

11

Backup and recovery

Encrypted remote backups are tested through an isolated restoration exercise. The 7 October 2026 exercise verified the deployed runtime schema, uploaded files, key rotation and authenticated application flows. A weekly exercise and freshness check are installed. Clean-host failover, DNS cutover and contractual recovery objectives require separate qualification.

12

Delivery and monitoring

Changes pass code, dependency and container security gates before controlled release. Runtime artifacts are signed and deployed by immutable digest through a staged rollout. Health checks, security events and operational evidence support review and incident handling. Human response commitments are agreed separately.

Define the protection you need.

Browser controls and watermarks help govern distribution. A person who can see a document can still photograph or capture a display. Stronger external DRM/IRM, supported formats and device restrictions require an agreed solution and evidence.

Application controls do not constitute SOC 2 or ISO 27001 certification. Regulatory responsibilities, subprocessors, data residency, retention, enterprise identity connections and incident response coverage are reviewed for the actual service and deployment.

Enterprise review

A dossier for your security team.

Request the versioned technical dossier covering architecture, tenant isolation, authentication, access permissions, cryptographic operations, document processing, audit, restoration evidence and the shared responsibility model.

The review also identifies the evidence needed for identity-provider integration, regional hosting, independent penetration testing, certification, host-loss recovery and contracted operational support.

Download technical dossier · French PDF

Edition 1.7 covers the deployed VDR, guided demos, committee reviews, scheduled reporting, buyer-team collaboration, storage adapters and document-retention controls, with their evidence and remaining enterprise qualifications. The PDF contains no customer data or credentials.

Compare deployment packages

Your email and request category are stored so the team can follow up. This request does not activate a subscription.