Security

Security is our
foundation

QueueHub was designed with a security-first mindset from day one. When you manage your queues through QueueHub, your data stays yours. We never store job payloads, never open inbound ports to your network, and never compromise on encryption standards.

Home/Security
Encryption

Protected at every layer

Your queue data is encrypted everywhere β€” in transit between your infrastructure and our dashboard, at rest in our systems, and inside the secure WebSocket tunnels that connect your agents.

🌐

TLS 1.3 in Transit

All communication between the QueueHub dashboard, our API, and your deployed agents is encrypted with TLS 1.3. We enforce strong cipher suites and disable outdated protocols. Every connection undergoes certificate pinning and mutual TLS verification where supported. There are no unencrypted fallback paths.

  • βœ“TLS 1.3 only (TLS 1.2 disabled on all endpoints)
  • βœ“HSTS preload with 2-year max-age directive
  • βœ“Certificate transparency logging for all certificates
  • βœ“Perfect Forward Secrecy (PFS) with ECDHE key exchange
πŸ”

AES-256 at Rest

Any data that passes through QueueHub's infrastructure is encrypted at rest using AES-256. This includes session metadata, connection configuration, and any cached or logged information. Encryption keys are managed through a hardware security module (HSM) with automatic rotation every 90 days.

  • βœ“AES-256-GCM encryption for all stored data
  • βœ“Key rotation every 90 days with automated HSM management
  • βœ“Encrypted database backups with separate key hierarchy
  • βœ“No persistent storage of job payloads or queue contents
Agent Relay

Connect without exposing your network

QueueHub's agent architecture is built on a zero-trust model. The agent never opens inbound ports β€” it connects to us over an outbound-only WebSocket tunnel. Your private network stays private.

πŸ”Œ

Outbound-Only Connections

The QueueHub agent initiates a single outbound WebSocket connection to our relay server. No inbound ports are opened on your infrastructure β€” no firewall rules, no NAT gymnastics, no VPNs. This eliminates an entire class of attack surface.

πŸͺͺ

Mutual TLS Authentication

Every agent authenticates with a unique client certificate issued during provisioning. Both the agent and the relay server verify each other's identity before a single byte of queue data is transmitted.

🧩

Least-Privilege Access

Agents are scoped to specific queues and actions at provisioning time. A monitoring agent only gets read access. A management agent can enqueue and retry jobs. No agent has blanket access to everything in your Redis instance.

Compliance

Certifications & standards

We're committed to meeting the highest industry standards for security and privacy. Here's where we stand today.

πŸ“‹
In Progress

SOC 2 Type II

We're currently undergoing SOC 2 Type II auditing. Expected completion is Q4 2025.

πŸ‡ͺπŸ‡Ί
Compliant

GDPR

Full compliance with the General Data Protection Regulation. Data processing agreements available on request.

πŸ…
In Progress

ISO 27001

ISO 27001 certification is in our roadmap for H1 2026. Our ISMS is already aligned with the standard.

Data Handling

Your data, your control

QueueHub is designed to be a read-through dashboard. Job payloads are streamed through the encrypted tunnel to your browser in real-time β€” we never store them on our servers. When you close a session, the data is gone.

The only information we persist is metadata necessary to operate the service: team configurations, agent provisioning records, and aggregated metrics (queue sizes, throughput, failure rates). None of this includes your application data, job payloads, or worker internals.

You can request a full data export or account deletion at any time. We process deletion requests within 30 days in accordance with GDPR requirements.

Data handling policy summary

Job payloadsNever stored β€” streamed in real-time only
Connection metadataStored encrypted β€” retained 90 days
Usage analyticsAnonymized β€” opt-out available in settings
Team & user dataStored encrypted β€” retained until deletion request
Audit logsStored encrypted β€” retained 1 year
Billing dataStored encrypted via PCI-compliant processor
Infrastructure

Enterprise-grade infrastructure

QueueHub runs on industry-leading cloud infrastructure with defense-in-depth security controls at every layer.

☁️

Cloud Hosting

AWS with dedicated VPCs, WAF, Shield Advanced DDoS protection, and network isolation between customers.

πŸ”‘

Access Control

SSO/SAML, SCIM provisioning, role-based access control (RBAC), and mandatory 2FA for all team accounts.

πŸ“

Audit Logging

Every action is logged with immutable audit trails. Export logs to your SIEM via webhook or API.

πŸ”„

Incident Response

24/7 security monitoring, automated threat detection, and a documented incident response plan tested quarterly.

Responsible Disclosure

Found a vulnerability?

We welcome responsible security researchers to help us keep QueueHub safe. If you've identified a security issue, please report it privately and we'll respond promptly.

How to report: Send an email to security@queuehub.tech with a detailed description of the vulnerability, including steps to reproduce, affected versions, and any proof-of-concept code. Please encrypt sensitive details using our PGP key (available on request).

Our commitment: We will acknowledge receipt within 24 hours, provide regular updates on our remediation progress, and never pursue legal action against researchers acting in good faith. We also offer a vulnerability bounty program for qualifying findings.

Safe harbor: We consider security research conducted under this policy as authorized activity. We will not take legal action against researchers who comply with this policy.

Have security questions?

Our security team is available to answer your questions, review our policies, or complete your vendor security assessment.