Verifying session…

← Back to HiveNet

Security at HiveNet

Last updated: 29 April 2026

Your business runs on data. If your team is going to use sensitive company information inside HiveNet, you need to know exactly how it’s handled — who can see it, who can’t, and what we’ll never do with it. This page is the plain-English version.

Our long-term plan is full data sovereignty in Australia — running the chat and bot servers on Australian-hosted infrastructure. We’re not there yet at our current scale; today we run in Hetzner’s Singapore region, with detail in §11.

The short version

1. Your data is yours

Any sensitive company information your team puts into HiveNet belongs to your business. We treat it that way. We will never:

2. Who can read your data

Three groups, in this order:

  1. Your people. The team members you invite to a room. You decide who’s in, who’s out, and when to remove them.
  2. Your bot. The AI assistant attached to your account. The bot is isolated from every other customer’s bot — one customer’s notes never surface in another’s session.
  3. The HiveNet support team, only with your permission. Logs may be accessed by our support team when you have raised a support ticket or a security investigation — the ticket is the permission. Every access is recorded with the operator’s name, the time, and the reason, and we keep those records for audit. The team able to do this is fewer than five named operators with hardware-key SSH access. We never access customer conversations for product improvement, model training, analytics, or curiosity.

3. What happens when you message your bot

Plain English version of the journey:

  1. You type a message in HiveNet. It travels to our server over an encrypted connection (HTTPS, behind Cloudflare).
  2. It’s saved as a chat message in our database, in a room only your invited team can see.
  3. Your bot reads it and decides what to do. To form an answer it sends the relevant text to an AI model (currently Anthropic’s Claude, with OpenAI, Google, or MiniMax as supporting models depending on the task).
  4. The model returns an answer. Your bot delivers it back into your room.

Your data does not stop in any analytics tool, marketing platform, or advertising network along the way. The AI providers we use have published commitments not to train on this data and to retain it only briefly for safety review. Full provider list and the quoted commitments are in the subprocessor section.

4. What we’d do if something went wrong

We don’t have a 24/7 security operations centre. We do have a clear set of commitments:

5. What you control


TECHNICAL DETAIL

The rest of this page is for IT, security, and procurement teams running their own checks. The plain-English commitments above are the contract.

6. Encryption

6.1 In transit

6.2 At rest

Honest answer: full-disk encryption on our PostgreSQL data volumes is on the roadmap, not in place today. What we do have:

7. Hosting & the private network

ServerRolePublic exposure
Chat serverMatrix server (Synapse), Element web UI, PostgreSQLPorts 80 & 443 only, behind Cloudflare
Bots serverBot containers (one per customer/persona), HiveBots middlewarePorts 80 & 443 only, behind Cloudflare

The two servers communicate over an isolated private network (10.0.0.0/24) inside Hetzner’s data centre. That network has no public route — it doesn’t exist on the internet. Concretely:

8. Subprocessors

Every third party that may process your data when you use HiveNet:

SubprocessorPurposeWhat it seesRegion
Hetzner Online GmbHCompute & storage (chat server, bots server, database)All data at rest on our infrastructureSingapore
Cloudflare, Inc.DNS, edge TLS, DDoS & WAF, application tunnelsHTTPS request metadata + ciphertext (terminates TLS at edge with our certificate)Global edge; nearest PoP serves the user
Anthropic, PBCPrimary chat model (Claude)Bot prompts & responses for the active turnUSA
OpenAI, L.L.C.Secondary chat modelBot prompts & responses for the active turnUSA
Google LLC(a) Gemini API for memory embeddings; (b) OAuth + Google Workspace APIs when you connect a Google accountEmbedding text; live Workspace data scoped to the OAuth grant you authorisedUSA / global
Microsoft CorporationMicrosoft 365 OAuth + Graph APIs when you connect a Microsoft accountLive Microsoft 365 data scoped to the OAuth grant you authorisedUSA / global
MiniMaxFallback chat model + conversation summarisationBot prompts & responses for the active turnSingapore / global
Namecheap (eForward)Inbound email forwarding for our public addressesEmail envelope + bodyUSA

Quoted training-data commitments:

If a provider materially changes its terms in a way that conflicts with these commitments, we’ll notify customers and switch providers if needed.

9. Authentication & access

10. Logging & retention

11. Where it physically runs

Today our infrastructure runs in Hetzner Cloud’s Singapore region. Singapore offers low latency to Australia, the same region for ANZ customers, a strong data-protection legal regime (the PDPA), and a price point that lets us self-host the open-source platform components without making the product unaffordable.

HiveBots PTY LTD is an Australian company. Full data sovereignty in Australia is on our roadmap. At our current scale, equivalent Australian-hosted compute would meaningfully change the price of the product. We’ll move when we can do it without making HiveNet inaccessible to small businesses, and we’ll tell customers in advance.

If you have a regulatory requirement that data must reside in Australia today, please tell us — we’d rather know now than later. A Data Processing Addendum is available on request.

12. What we haven’t done yet

We don’t want to oversell. As of this page’s date:

If any of those are blockers for you, please tell us — we’d rather know early.

13. Reporting a concern

Found a vulnerability or have a worry about how data was handled? Email [email protected]. We aim to acknowledge within one business day. Machine-readable disclosure contact at /.well-known/security.txt on our public site.

Privacy PolicyDPA on requestHosted in Singapore (Hetzner)Australian sovereignty on the roadmap

For the legal basis on which we collect and process personal data, see our Privacy Policy. This page applies to HiveNet, operated by HiveBots PTY LTD (Australia).