Security & compliance

A monitoring tool
has to be beyond reproach

HubPlace sees inside your IT estate. We take that responsibility seriously: here is exactly how your data is handled.

Hosted in France

The application servers and the database are located in France, with a European operator. No data is transferred outside the European Union.

Encryption in transit

Every exchange — browser and agents alike — goes over HTTPS/TLS. Passwords are hashed with bcrypt and never stored in clear text.

Tenant isolation

Each organisation has its own perimeter. A request cannot cross an organisation boundary, not even through a mistyped URL.

Fine-grained rights

Each module (estate, health, tickets, projects, applications) is enabled independently per user or per group.

Protected secrets

The technical credential vault stores passwords encrypted; every reveal is logged.

Traceability

Administration actions are logged, and the change history of each endpoint is kept for the period you define.

The agent

No way in to your endpoints

This is the first thing IT managers check: the HubPlace agent listens on no port and accepts no inbound connection.

  • Outbound connections onlyThe agent calls HubPlace over HTTPS, exactly like a browser. No inbound firewall rule is needed.
  • Readable codeThe agents are PowerShell and Bash scripts: your team can review them before any deployment.
  • One key per endpointThe site token is only used for enrolment. Each endpoint then receives its own key, revocable individually.
  • Technical data onlyNo file contents, no documents, no screenshots and no keystrokes are ever collected.
Two technicians reviewing the status of a server rack in a data centre.

HubPlace and the GDPR

HubPlace processes a limited volume of personal data: that of your users (name, work email address) and the link between an endpoint and a person. Here is the applicable framework.

Roles

Thiris, the publisher of HubPlace, acts as a processor within the meaning of Article 28 of the GDPR. You remain the controller for your users' and your estate's data.

Purpose

Data is processed for the sole purpose of delivering the service: inventory, monitoring, support and project management. It is never sold, never used for advertising and never used to train models.

AI analysis

Health analysis sends anonymised technical indicators to an AI model (usage rates, pending patches, drive status). No user name and no file content is sent.

Retention

Monitoring data is kept for the period you configure, up to twelve months by default. Deleting your workspace permanently erases your data.

Your rights

Access, rectification, erasure, portability and restriction can be exercised from your workspace or on request to our contact address. We respond within thirty days.

Sub-processors

The list of technical providers (hosting, email and SMS delivery, AI analysis) is available on request and kept up to date.

Security questions

Can another customer see my data?

No. Every query is filtered on the signed-in user's organisation, at database level. There is no cross-tenant view available to customers.

Who at Thiris can access my data?

Only technical administrators, for operations and support purposes, and only when necessary. Those accesses are logged.

What happens if I leave HubPlace?

You export your data to Excel, then request deletion of your workspace. Erasure is permanent and confirmed in writing.

Do you provide a signed data processing agreement?

Yes. A processing agreement compliant with Article 28 of the GDPR is available on request, along with a description of the technical and organisational measures.

Is remote access secure?

Optional remote access runs through an encrypted outbound tunnel initiated by the appliance on your network. It is disabled by default.

A question we haven't anticipated?

Write to us: we answer precisely, including to your IT department's security questionnaires.