Security & compliance roadmap

This page is maintained by HuntBug Inc. to answer common security and privacy questions about the HuntBug platform. It describes controls that are live in the product today and our staged plan toward SOC 2 readiness. It is not a certification, an audit report, or independent verification.

Security on HuntBug is shared: our hosting providers secure the underlying infrastructure, HuntBug secures the application and how report data is handled, and customers are responsible for their own account hygiene — strong credentials, two-factor enrolment, and who they grant program access to.

Controls in place today

Everything below is implemented and visible in the product.

Authentication

Email/password and Google sign-in, with TOTP two-factor available for researchers and company accounts. Sensitive account changes require a recent, step-up authenticated session.

Authorization

Row-level access rules on every data table. Researchers see only their own reports; company members see only programs assigned to their organisation; staff actions are role-gated.

Report confidentiality

Report bodies, attachments and thread messages are private to the reporter, the assigned triage staff and the owning company. Email notifications are content-free — they never include message text.

Internal notes

Notes marked internal are filtered server-side and are never delivered to the reporting researcher.

Sensitive data at rest

Payout details, KYC and tax submissions are stored encrypted with per-record initialisation vectors; only masked identifiers are shown in the UI.

Attachments

Proof-of-concept files live in a private bucket, are scoped to the uploader's path, and are served only through short-lived signed URLs.

Audit logging

Privileged actions — bans, forced status transitions, program access changes — are written to an append-only audit log that cannot be edited or deleted from the app.

Vulnerability intake

HuntBug runs its own disclosure channel at /responsible-disclosure and publishes a security.txt.

Roadmap to SOC 2

Phase 0 — Security foundations

Complete
  • Row-level access rules across all application tables
  • Encryption at rest for payout, KYC and tax records
  • Two-factor authentication (TOTP) for researcher and company accounts
  • Append-only audit log for privileged actions
  • Content-free notification emails on an authenticated sending domain

Phase 1 — Policy & governance

In progress
  • Written information security policy set (access control, change management, incident response, vendor management)
  • Documented onboarding/offboarding and least-privilege access reviews
  • Formal risk assessment and register, reviewed quarterly
  • Sub-processor register published on this page
  • Security awareness training for everyone with production access

Phase 2 — Monitoring & evidence

Next
  • Continuous control monitoring tooling wired to identity, code and cloud providers
  • Centralised logging with alerting on privileged and anomalous activity
  • Backup and restore testing on a documented schedule
  • Annual third-party penetration test with a published summary letter
  • Formal incident-response runbook with tabletop exercises

Phase 3 — SOC 2 Type I

Planned
  • Readiness assessment and gap remediation with an independent auditor
  • Point-in-time Type I report covering Security (and Confidentiality) criteria
  • Report available to customers and prospects under NDA

Phase 4 — SOC 2 Type II & beyond

Planned
  • Observation window of at least three months, then Type II report
  • Annual renewal cadence
  • ISO 27001 and GDPR DPA package evaluated based on customer demand

Roadmap phases describe intent and are subject to change. Target dates are shared under NDA during procurement rather than published here.

Frequently asked

Is HuntBug SOC 2 certified today?
No. HuntBug is not SOC 2 certified and holds no third-party security certification at this time. This page describes the controls that are live in the product today and the staged plan to reach SOC 2 readiness. Nothing here should be read as an audit result.
Can I get a security questionnaire completed?
Yes — email the security contact below and we will complete standard questionnaires (CAIQ, SIG Lite or your own) with current, accurate answers.
Where is data hosted?
HuntBug runs on managed cloud infrastructure with data stored in a managed Postgres database and object storage. Ask us for the current region and sub-processor list before signing.
How do we report a vulnerability in HuntBug itself?
Use our responsible disclosure page or the address in our security.txt. We acknowledge reports and keep reporters updated through resolution.
Security contact
Security questions, questionnaires and vulnerability reports: gethuntbug@gmail.com.