Product/Security & Compliance

Trust, built into every layer.

Fleet control is a privileged position, and Hive treats it that way. Per-device identity, signed commands, strict tenant isolation, and an immutable audit log for every action taken.

Architecture

Security in every layer

From the device to the console, every layer of the platform is designed against the assumption that fleet control is worth attacking.

01

Platform Security Architecture

A defence-in-depth design spanning device, transport, and control-plane layers, reviewed continuously against new threats.

Explore →
02

Per-Device Identity & Certificates

Every enrolled device gets a unique cryptographic identity: no shared secrets, no credential to steal fleet-wide.

Explore →
03

Encryption In Transit & At Rest

TLS 1.3 for every connection, AES-256 for data at rest, on the device, in transit, and in the console.

Explore →
04

Signed Commands, Policies & Apps

Every command, policy push, and application package is cryptographically signed before a device will act on it.

Explore →
05

Tenant Isolation

Hard boundaries between organisations at the data and infrastructure layer: no cross-tenant visibility, ever.

Explore →
06

SSO & MFA

SAML and OIDC single sign-on with enforced multi-factor authentication for every console user.

Explore →
Access control

Least privilege, always enforced

01

Role-Based Access Control

Every console user gets exactly the scope they need: nothing implied, nothing inherited by accident.

  • Granular roles scoped by organisation, site, or group
  • Custom roles for support, engineering, and read-only auditors
  • SCIM provisioning synced from your identity provider
02

Approval Gates for Destructive Actions

Wipes, factory resets, and fleet-wide commands can require a second approver before they ever reach a device.

  • Configurable approval requirements per action type
  • Second-approver sign-off for fleet-wide or irreversible commands
  • Full approval chain recorded against the resulting action
Accountability

Nothing happens off the record

Every command, config change, and remote session is written to a log no one, including Hive, can edit or delete.

By the numbers

Verified, not assumed

Commands cryptographically signed
100%Commands cryptographically signed
Deployment modes: cloud, private cloud, on-prem, air-gapped
4Deployment modes: cloud, private cloud, on-prem, air-gapped
Audit log retention
7yrAudit log retention
Control plane architected for high availability
ResilientControl plane architected for high availability
Certifications

Security-first, by design

Hive practises continuous vulnerability management, with third-party penetration testing and formal certifications like SOC 2 and ISO 27001 on our roadmap as we grow.

Security-First Architecture Continuous Vulnerability Management GDPR-Aligned Practices

Found a vulnerability? We run a responsible disclosure programme and credit every valid report. Reach the security team directly at security@hivemdm.com.

Related

Keep exploring

Trust Centre

Certifications, sub-processors, and security documentation in one place.

Explore →

Integrations

See how Hive connects to your identity provider, ITSM, and incident tooling.

Explore →

Product Overview

See how security underpins every capability across the fleet lifecycle.

Explore →