Security is our
foundation
QueueHub was designed with a security-first mindset from day one. When you manage your queues through QueueHub, your data stays yours. We never store job payloads, never open inbound ports to your network, and never compromise on encryption standards.
Protected at every layer
Your queue data is encrypted everywhere β in transit between your infrastructure and our dashboard, at rest in our systems, and inside the secure WebSocket tunnels that connect your agents.
TLS 1.3 in Transit
All communication between the QueueHub dashboard, our API, and your deployed agents is encrypted with TLS 1.3. We enforce strong cipher suites and disable outdated protocols. Every connection undergoes certificate pinning and mutual TLS verification where supported. There are no unencrypted fallback paths.
- βTLS 1.3 only (TLS 1.2 disabled on all endpoints)
- βHSTS preload with 2-year max-age directive
- βCertificate transparency logging for all certificates
- βPerfect Forward Secrecy (PFS) with ECDHE key exchange
AES-256 at Rest
Any data that passes through QueueHub's infrastructure is encrypted at rest using AES-256. This includes session metadata, connection configuration, and any cached or logged information. Encryption keys are managed through a hardware security module (HSM) with automatic rotation every 90 days.
- βAES-256-GCM encryption for all stored data
- βKey rotation every 90 days with automated HSM management
- βEncrypted database backups with separate key hierarchy
- βNo persistent storage of job payloads or queue contents
Connect without exposing your network
QueueHub's agent architecture is built on a zero-trust model. The agent never opens inbound ports β it connects to us over an outbound-only WebSocket tunnel. Your private network stays private.
Outbound-Only Connections
The QueueHub agent initiates a single outbound WebSocket connection to our relay server. No inbound ports are opened on your infrastructure β no firewall rules, no NAT gymnastics, no VPNs. This eliminates an entire class of attack surface.
Mutual TLS Authentication
Every agent authenticates with a unique client certificate issued during provisioning. Both the agent and the relay server verify each other's identity before a single byte of queue data is transmitted.
Least-Privilege Access
Agents are scoped to specific queues and actions at provisioning time. A monitoring agent only gets read access. A management agent can enqueue and retry jobs. No agent has blanket access to everything in your Redis instance.
Certifications & standards
We're committed to meeting the highest industry standards for security and privacy. Here's where we stand today.
SOC 2 Type II
We're currently undergoing SOC 2 Type II auditing. Expected completion is Q4 2025.
GDPR
Full compliance with the General Data Protection Regulation. Data processing agreements available on request.
ISO 27001
ISO 27001 certification is in our roadmap for H1 2026. Our ISMS is already aligned with the standard.
Your data, your control
QueueHub is designed to be a read-through dashboard. Job payloads are streamed through the encrypted tunnel to your browser in real-time β we never store them on our servers. When you close a session, the data is gone.
The only information we persist is metadata necessary to operate the service: team configurations, agent provisioning records, and aggregated metrics (queue sizes, throughput, failure rates). None of this includes your application data, job payloads, or worker internals.
You can request a full data export or account deletion at any time. We process deletion requests within 30 days in accordance with GDPR requirements.
Data handling policy summary
Enterprise-grade infrastructure
QueueHub runs on industry-leading cloud infrastructure with defense-in-depth security controls at every layer.
Cloud Hosting
AWS with dedicated VPCs, WAF, Shield Advanced DDoS protection, and network isolation between customers.
Access Control
SSO/SAML, SCIM provisioning, role-based access control (RBAC), and mandatory 2FA for all team accounts.
Audit Logging
Every action is logged with immutable audit trails. Export logs to your SIEM via webhook or API.
Incident Response
24/7 security monitoring, automated threat detection, and a documented incident response plan tested quarterly.
Found a vulnerability?
We welcome responsible security researchers to help us keep QueueHub safe. If you've identified a security issue, please report it privately and we'll respond promptly.
How to report: Send an email to security@queuehub.tech with a detailed description of the vulnerability, including steps to reproduce, affected versions, and any proof-of-concept code. Please encrypt sensitive details using our PGP key (available on request).
Our commitment: We will acknowledge receipt within 24 hours, provide regular updates on our remediation progress, and never pursue legal action against researchers acting in good faith. We also offer a vulnerability bounty program for qualifying findings.
Safe harbor: We consider security research conducted under this policy as authorized activity. We will not take legal action against researchers who comply with this policy.
Have security questions?
Our security team is available to answer your questions, review our policies, or complete your vendor security assessment.