HiveBots infrastructure is architected, built, maintained and continuously improved by Australian AI and cyber-security professionals. It is independently penetration-tested, continuously verified by automated controls, and treated as a product feature. Our controls are designed and operated to satisfy SOC 2 requirements.
Your data is yours
- We never sell it, rent it, or pass it to anyone for commercial benefit.
- We never use it for advertising or profiling.
- One agency’s data never surfaces in another’s bot: every organisation and every bot is isolated.
- It is never used to train AI models. Ours or anyone else’s, with zero-retention and zero-training enterprise API agreements in place.
Who can read your data
- Your people. The team members you invite. You decide who is in and who is out.
- Your bot. The assistant attached to your account, isolated from every other customer’s.
- HiveBots support, only with your permission. A support ticket you raise is the permission; every access is logged with the operator, time and reason.
The Microsoft 365 and Google integrations
- Delegated permissions only. Bots act on behalf of the signed-in user through Microsoft Graph delegated scopes, never application-level tenant-wide access. A bot sees only what its own human can see, and your Entra ID controls (Conditional Access, MFA, security-group assignment) apply unchanged.
- Your files stay in your tenant. Documents, mail and calendars remain in your own SharePoint, OneDrive and Exchange. HiveNet is an operational interface: it fetches what a live request needs and does not store persistent copies of your company files.
- A human approves external actions. Bots cannot send email or take other irreversible actions without explicit sign-off from their human.
- Revocation is instant. Disable the enterprise application or user assignment in Entra ID, or disconnect in the bot’s panel, and access stops immediately.
Where your data lives
- Your company files: in your own Microsoft 365 or Google tenant. They are not copied into HiveNet.
- Critical platform data (team memories, skills, connector logs and platform backups) is stored in our Australian data centre for data residency.
- Chat endpoints are served from our Singapore-region infrastructure for availability and low latency, so your network team may observe HiveNet traffic routed to Singapore. Your company files never move there.
A Data Processing Addendum is available on request.
Encryption and platform controls
- TLS 1.3 in transit; HSTS enforced; DDoS and WAF protection at the edge.
- Credentials and OAuth tokens encrypted at rest with AES-256-GCM.
- Per-organisation and per-bot isolation, enforced structurally, not just by policy.
- Least-privilege operations: production access is limited to a small number of named engineers using hardware-backed keys, and every fleet operation leaves an audit trail.
- Closed registration: accounts are provisioned after we verify the customer.
- MFA available today by signing in with your Microsoft or Google work identity, inheriting your Conditional Access and MFA policies.
How we verify it
- Independent penetration testing. HiveNet was penetration-tested in May 2026; every finding was remediated the same day and regression-tested since.
- Recurring security audits of the whole platform, with tracked, closed findings.
- Continuous monitoring. Automated controls check the platform and its public surfaces around the clock and alert on-call: auth gates, public exposure, key hygiene, and that this page says what we claim.
As a Microsoft Partner Network member (MPN ID 7149335), our Entra applications carry Microsoft’s verified-publisher stamp: the consent screens your IT team sees are cryptographically tied to HiveBots PTY LTD.
Subprocessors
| Provider | Purpose |
|---|---|
| Hetzner | Cloud infrastructure hosting |
| Cloudflare | Edge security, TLS, DDoS protection |
| OpenAI | AI inference (zero data retention, zero training) |
| AI models and Workspace APIs (zero training) | |
| Microsoft | Microsoft 365 and identity APIs |
What you control
- Export your data (configuration, skills, memories, chat history) at any time. You never start from scratch elsewhere.
- Purge on request: we delete your data and confirm it in writing.
- Revoke integrations instantly from Entra ID, Google admin, or the bot’s panel.
- Customer-managed keys (BYOK) available for enterprise agreements on request.
Reporting a concern
Found a vulnerability, or have a worry about how data was handled? Email hello@hivebots.com.au. We acknowledge within one business day. Machine-readable disclosure contact at /.well-known/security.txt.
For the legal basis on which we collect and process personal data, see our Privacy Policy and Terms of Service. This page applies to HiveNet, operated by HiveBots PTY LTD (Australia).