AES-256
Encryption at rest
TLS 1.3
Encryption in transit
99.9%
Uptime SLA
Daily+
Automated backups
Applies across the suite
One security foundation. Every product built on it.
Hutstack Work
Operations, HR, finance — same encrypted foundation.
Hutstack PMS
Tenant data, leases, accounting — same protections, end-to-end.
Security measures
Enterprise-grade safeguards.
For every customer.
You shouldn't need to be a Fortune 500 to have proper protections. Every Hutstack plan ships with the same security baseline.
Encryption at rest & in transit
All data is encrypted at rest with AES-256 — the standard used by banks and governments — and protected in transit with TLS 1.3, preventing interception.
Role-based access control
Every team member sees only what they need. Configure granular permissions by role — admin, manager, accountant, viewer — so sensitive data stays scoped.
Two-factor authentication
Protect every account with 2FA via authenticator app or SMS. Admins can enforce 2FA across all members in organisation settings.
Automated backups
Data is backed up multiple times per day, replicated across regions, and tested for recoverability. Your data is always restorable.
Immutable audit logs
Every meaningful action is logged — who, what, when. Full audit trails for access, edits, and exports support accountability and dispute resolution.
Resilient infrastructure
Multi-region redundancy, monitored availability, transparent incident reporting. We've engineered for the realities of the work you depend on us for.
Least-privilege internal access
Hutstack staff cannot view customer data by default. Production access is gated, logged, and time-bound — and only granted for support cases you initiate.
Regional data residency
Data is stored in regions serving West Africa where possible — minimising latency and keeping your operational data geographically close.
Compliance & assurance
Held to the standards your business is.
01
SOC-aligned practices
Security, availability, and confidentiality practices aligned with SOC 2 Trust Service Criteria. Regular internal reviews and vulnerability assessments.
02
GDPR-aligned privacy
Designed around international data privacy principles. Customers retain the right to access, correct, and understand how their data is used.
03
Annual penetration testing
Independent security professionals attempt to break Hutstack at least once a year. Findings are remediated and tracked to closure.
04
Vulnerability disclosure
Security researchers can responsibly disclose issues at [email protected]. We respond within one business day and credit fixes publicly.
Our promises
Four commitments you can hold us to.
Security isn't a checklist on a marketing page. These are commitments — and we'll put them in writing.
- Your data is yours. You can export it at any time, in clean formats.
- We never sell, lease, or rent customer data — full stop.
- We notify you within 72 hours of any security incident affecting your account.
- Production access by Hutstack staff is time-bound, logged, and requires customer-initiated reason.
Security team
Have a security question or specific requirement?
Penetration test results, custom DPAs, vendor security questionnaires — our team handles them all. We respond within one business day.