Security & Trust

How Hubswire handles your data

Hubswire sits between your team's Microsoft 365 mailboxes and your ERP. This page explains where data flows, where it is stored, who can see it, and what we do not claim yet.

Data flow

  1. 1
    Your mailbox, through Microsoft GraphHubswire reads and sends mail with Microsoft's official Graph API, using the access your Microsoft 365 administrator or users grant with OAuth. Hubswire does not see Microsoft 365 passwords.
  2. 2
    Hubswire cloud (Microsoft Azure, United States)Messages, attachments, comments and settings are stored in Hubswire's Azure environment so your team can share inboxes, assign, comment and search.
  3. 3
    ERP bridge agent, on your networkA small agent installed on your server connects out to Hubswire and answers read-only lookups against your ERP (for example Descartes OneView data on Pervasive / Actian Zen).
  4. 4
    AI providers, only for AI featuresWhen a user runs an AI feature, a trimmed excerpt of the relevant email is sent to OpenAI or Google Gemini through their APIs. See AI providers.
  5. 5
    Tracking providers, identifiers onlyContainer, bill of lading and air waybill numbers found in email are sent to tracking providers (OpenTrack, Portcast, Terminal49, project44, SeaRates, MarineTraffic and PortPro) to get shipment status. Email bodies are not sent.

Hosting & encryption

  • Hosting: Microsoft Azure in the United States (West US 2 region). File storage is geo-replicated to a second US region (West Central US).
  • In transit: traffic between your browser or desktop app and Hubswire, and between Hubswire and its providers, uses HTTPS/TLS.
  • At rest: the database and file storage use Azure platform encryption. OAuth refresh tokens and third-party API keys are also encrypted by the application before they are stored.
  • Backups: automated database backups with point-in-time recovery.

AI providers

OpenAI

Used through the API for fast tasks such as reply drafts and classification. Default model: gpt-4o-mini.

Google Gemini

Used through the API for heavier tasks such as summaries and document classification, including Gemini 2.5 Pro.

  • No training on your data. We use the providers' API terms, under which content submitted through the API is not used to train their models.
  • Minimized input. Where a feature does not need the whole email, only a trimmed excerpt is sent, and signatures are stripped before sending.
  • You can turn it off. Account administrators can configure which AI features are enabled for their company.

Access control & audit logging

  • Sign-in with Microsoft. Users sign in with their Microsoft 365 work account.
  • Roles. Company administrators and members have different permissions, and access to shared inboxes is granted per inbox.
  • Audit log. Changes made in the app are recorded in an audit log, and every ERP query is logged with a SHA-256 hash of the query text.
  • Hubswire staff. Production access is limited to a small number of named people.

ERP bridge agent

The agent is how Hubswire shows ERP data (file numbers, documents, references) next to the email that mentions it, without opening your network.

  • Outbound-only. The agent opens an outbound, authenticated connection to Hubswire. You do not open inbound firewall ports or change firewall rules.
  • Read-only queries. The agent rejects anything other than SELECT queries.
  • One-time pairing code. The agent is paired with your Hubswire account using a single-use pairing code; after pairing the code is cleared.
  • Document upload only when a user asks. The only write is the optional "upload document" action: when an authorized user chooses to send an email attachment to the ERP, the agent adds that document through the ERP's own document API.
  • Logged. Queries are recorded in an audit log with a SHA-256 hash of each query.

Compliance roadmap

SOC 2 Not certified

Hubswire does not currently hold a SOC 2 report or any other security certification. SOC 2 readiness is on our roadmap.

Our Data Processing Agreement is available on request at privacy@hubswire.com. We can also answer security questionnaires on request. Write to security@hubswire.com.

Responsible disclosure

If you believe you have found a security vulnerability in Hubswire, email security@hubswire.com with the details and steps to reproduce. Please give us reasonable time to fix it before you share it publicly, and do not access other customers' data. Our contact details are also in /.well-known/security.txt.

Subprocessors

The full list of subprocessors (Microsoft Azure and Microsoft 365, OpenAI, Google, tracking providers and others), what data each one receives, and where it is located is in Section 4 of our Privacy Policy.