Home/Security & trust
Security & trust

Control is the product.

Hubson is built so AI can do real work without becoming a liability. Access is scoped, risky actions pause for a human, and every important live run leaves a readable Action Receipt. You bring your own AI keys, and you can prove a workflow on sample data before a single live app or system is touched.

hubson · Control Hub · controls
Enforcedcontrol · scope
Scoped app actions
Hubson can read, draft, update, or ask to act only within the scope approved for each connected app.
Restricted actions · blocked by policy
Enforcedcontrol · approvals
Approval policy
Customer-facing, financial, and destructive actions pause for a human to approve, edit, or decline.
Refunds · approval above $2,000
Enforcedcontrol · evidence
Action Receipts
Every important live run leaves a readable receipt — with model usage shown, on your own keys where supported.
Receipt · R-1284Exportable
Data & control path

Where your data goes, and where control sits

1User request
2Hubson workflow
3Approved SOP / context
4Scoped app actions
5Selected model provider
6Approval gate
7Activity / Action Receipt
  • Hubson reads only what the workflow needs
  • Hubson acts only through approved actions
  • Risky actions pause for a human
  • Receipts record what happened
How your data is protected

Six controls under every workflow

The same controls that make Hubson trustworthy are the ones you configure and can see.

SCOPE

Scoped app access

Hubson shows exactly what it can read, draft, update, or ask to do in each connected app — and nothing beyond it.

APPROVALS

Humans hold authority

Customer-facing, financial, and destructive actions pause for the right person to approve, edit, or decline.

POLICY

Restricted actions blocked

Actions you mark off-limits are blocked by the workflow's action policy and can't run unless an owner changes it. Policy changes are limited to authorized workflow owners or admins.

BYOC

Bring your own keys

Use your own compute and model keys where supported. Model usage is shown transparently in every receipt.

MINIMIZE

Only the context it needs

A workflow pulls the specific context its SOP calls for — not blanket access to everything in an app.

EVIDENCE

Receipts as proof

Every important run leaves Activity and a readable Action Receipt you can export for finance, security, or a customer.

Data handling

What we do — and don't — do with your data

Simulate before live

Map, draft, and run any workflow on sample data and mock app responses before connecting a single live app or system.

Connect only what a workflow needs

Add app connections per workflow, and remove them when a workflow no longer runs.

No training on your data

Hubson does not use your organization data, SOPs, or run content to train shared models. Model-provider handling depends on the model provider and configuration you choose.

No silent actions

Nothing customer-facing, financial, or destructive runs without either an allowed policy or a human approval — and it's recorded.

Organization governance

Governed at the organization level,
not per prompt

People, roles, access, model accounts, credentials, app connections, and budgets are governed by the organization — so trust doesn't depend on every user configuring things correctly.

PEOPLE & ROLES

Who can do what

Roles decide who can create workflows, change policies, approve risky actions, and administer the organization.

CREDENTIALS & MODELS

Keys held by the org

Model accounts and app credentials are managed at the organization level — bring your own keys where supported, and rotate or revoke them in one place.

BUDGETS

Spend under control

Run capacity and budgets are set by admins, with warnings before limits and approval required to add capacity.

  • App/action health shows missing permissions and stale credentials before a live run fails
  • Only authorized owners or admins can change risk controls and action policy
  • Receipts are exportable for finance, security, or customer review
Honest boundaries

What Hubson is — and isn't

Hubson is

  • a controlled workflow layer — with SOPs, scoped actions, approvals, Activity, and readable receipts

Hubson is not

  • a replacement for legal, compliance, or security review
  • a reason to give AI blanket app access
  • a fully autonomous employee
  • a guarantee that every AI output is correct
Have a security question?

See the controls in action before you connect anything

Run a workflow as a simulation, review the Action Receipt, and set the scope and approvals you're comfortable with — then decide what to connect live.