Security & Compliance.
Last updated: August 28, 2026
Security is built into how we run MultiHub. This page gives a high-level overview of the practices we use to keep customer data protected. If you have questions, or if your security team needs more detail for a vendor review, contact us at support@multihub.io.
Cloud infrastructure.
MultiHub runs entirely on leading cloud infrastructure; we do not operate our own physical servers or data centers. The platform runs on Google Cloud Platform, using managed, containerized services. Google Cloud maintains extensive physical and network security controls and industry certifications:
Customer websites built with VibeSites are served through Cloudflare’s global edge network, which provides built-in distributed denial-of-service (DDoS) mitigation and keeps sites fast and available worldwide.
Network security.
Production databases run on private networks and are not exposed to the public internet. Application secrets and credentials are stored in a managed secret store, not in code, and are injected into services at deploy time. Firewalls and provider-level network controls restrict traffic between services.
Data encryption.
In transit: All data sent to or from our infrastructure is encrypted in transit using Transport Layer Security (TLS).
At rest: Data stored in our databases and storage systems is encrypted at rest by our cloud providers using industry-standard encryption. Passwords are never stored in plain text; they are hashed and salted using bcrypt, an industry-standard algorithm.
Account security.
Single sign-on: Sign in with Google is supported, so your team can use your organization’s existing Google account security.
Two-factor authentication: Users can enable two-factor authentication on their accounts. In addition, sign-ins from a new device or location trigger an email verification code before access is granted.
Brute-force protection: Accounts are temporarily locked after repeated failed sign-in attempts.
Session security: Sessions use secure, HTTP-only cookies and expire automatically.
Role-based access control.
MultiHub provides role-based access control at every level of your portfolio. Users are granted roles scoped to an agency, a company, or an individual property, so each person sees and manages only what their role allows.
Backups, continuity, and disaster recovery.
Production databases are backed up automatically every day to support recovery in the event of a disaster. Backups are encrypted at rest by our cloud providers.
Monitoring and alerting.
We monitor our infrastructure and applications continuously. Automated alerts notify our engineering team of anomalies and critical errors in real time, and we collect and retain application logs to provide an audit trail of activity.
Secure development.
We develop against recognized security frameworks and best practices, including the OWASP Top 10. Every code change is reviewed by another engineer before release.
Payment information.
We do not collect or store payment card information through the MultiHub platform. Billing is handled through invoicing, and payments are processed through our accounting provider’s PCI-compliant systems.
Employee access.
Internal access to customer data follows the principle of least privilege. Access is limited to employees who need it to do their jobs, with limited exceptions for customer support performed on your behalf. All employees sign confidentiality agreements when they join Repli.
Data retention and removal.
Customers can request removal of their data by contacting support@multihub.io. For details on how we collect, use, and retain personal information, see our Privacy Policy.
Responsible disclosure.
If you believe you have found a security vulnerability in MultiHub, we want to hear about it. Report it to security@multihub.io with enough detail for us to reproduce the issue. We will acknowledge your report, investigate promptly, and keep you informed as we address it. We ask that you give us a reasonable opportunity to remediate before public disclosure.
Questions.
Have questions or need security documentation for a vendor review? Reach out at support@multihub.io.
