Back to home

Trust & Security

Trust & Security

ND Hub is designed to help providers manage sensitive operational and participant information responsibly. This page explains, in plain English, how access, authentication and data protection are handled within the platform.

Security overview

How ND Hub protects information

Secure sign-in

ND Hub uses secure authentication services to verify users and manage account access. Supported sign-in methods include email & password (with password-reset by email) and Google sign-in. Users should never share passwords or authentication codes with another person.

New passwords are checked against known-compromised password databases and rejected if they appear in a public breach list.

Access controls

Roles are stored separately from user profiles and evaluated on the server for every protected request. Database access rules help prevent users from accessing records outside their authorised organisation or role.

Administrative actions such as role grants and permission changes are recorded in internal audit logs for review.

Data transmission

Data sent between your browser and ND Hub is protected using encrypted HTTPS connections. API calls to backend services and third-party integrations are made over TLS.

Data storage and infrastructure

ND Hub uses established cloud infrastructure and managed technology services to operate core parts of the platform, including database, authentication, storage and payments processing.

Selected platform services are powered by Supabase. Payments are processed by Stripe. These providers are named for transparency; listing them does not imply endorsement of ND Hub by those companies.

Participant and provider information

Provider organisations remain responsible for deciding what information is entered into ND Hub and who receives access to it.

Access should be limited to people who genuinely require the information for their work. Organisations should promptly remove access when a staff member or contractor no longer requires it.

Documents and uploads

Uploaded files are stored in private storage buckets that are not publicly listable. Downloads are served through short-lived signed URLs so links cannot be shared indefinitely.

The optional Document Vault applies client-side encryption to files before they are uploaded, so vault contents remain encrypted while stored.

Account responsibilities

  • Use a strong, unique password.
  • Do not share login credentials.
  • Review staff access regularly.
  • Sign out on shared devices.
  • Report suspected unauthorised access immediately.
  • Avoid entering information that is unnecessary for the task being completed.

Security FAQ

Short answers to common questions about how ND Hub protects your information.

How do I sign in securely?

ND Hub supports email & password sign-in (with password reset by email) and Google sign-in. New passwords are checked against known-breach lists and rejected if compromised.

See secure sign-in

Who can see my organisation's data?

Access is governed by roles stored separately from user profiles and enforced on the server for every request. Database rules help prevent users from reading records outside their authorised organisation or role.

See access controls

Is my data encrypted in transit?

Yes. Traffic between your browser and ND Hub uses HTTPS, and backend/API calls to integrated services are made over TLS.

See data transmission

Where is the platform hosted?

ND Hub runs on established managed cloud services. Core platform services are powered by Supabase and payments are processed by Stripe.

See data storage and infrastructure

How are uploaded documents protected?

Files are stored in private buckets that are not publicly listable, and downloads use short-lived signed URLs. The optional Document Vault encrypts files on your device before upload.

See documents and uploads

Does ND Hub hold SOC 2, ISO 27001 or HIPAA certification?

ND Hub does not currently claim SOC 2, ISO 27001, PCI, HIPAA or GDPR certification. The platform describes the technical safeguards actually in place rather than relying on third-party badges.

What should I do if I suspect an account has been accessed without permission?

Contact us immediately using the security contact on this page. Do not include participant records, passwords or authentication codes in the initial email.

Report a security concern

Where can I read the Privacy Policy?

The Privacy Policy describes what information is collected, how it is used, retained and disclosed.

See privacy and data handling

Privacy and data handling

ND Hub aims to collect and process only the information required to provide its platform functions. More detailed information about collection, use, retention and disclosure is contained in the ND Hub Privacy Policy.

Report a security or privacy concern

If you believe an ND Hub account or information may have been accessed without permission, use the form below to reach our security contact. Do not include participant records, passwords, authentication codes or other highly sensitive information in your report.

Report a security concern

Fields marked * are required. Do not include passwords or authentication codes.

Optional
Between 20 and 5000 characters.

Your report is sent directly to our security contact.

Security is a shared responsibility

No online platform can guarantee absolute security. ND Hub combines technical safeguards, controlled access and responsible operating practices to reduce risk. Provider organisations also need appropriate internal policies, staff training and access-management procedures.

Last reviewed: November 2026