> ## Documentation Index
> Fetch the complete documentation index at: https://docs.get-hive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security overview

> How Hive protects your business: tenant isolation, encrypted credentials, a deterministic policy engine between AI and action, approvals, audit and a kill switch.

Hive connects to the systems that run your business and can act in them. Security is therefore not a feature bolted on at the end: it shapes how every part of the product is built. This page summarises the protections in place today. The pages that follow go deeper.

## The core principle: the AI proposes, rules decide

Hive's AI never holds your credentials and never executes anything directly. Every action follows the same path:

```mermaid theme={null}
flowchart LR
  S[Signal or request] --> P[AI plans a typed proposal]
  P --> G{Deterministic policy engine}
  G -->|Within limits| X[Isolated executor<br/>holds credentials]
  G -->|Needs a person| A[Approval]
  G -->|Not allowed| H[Shadow: simulated only]
  A -->|Approved| X
  X --> L[Audit log receipt]
```

* **Proposals are typed.** The model can only propose actions from an allow-list of known action types, with structured parameters — not free-form commands.
* **Policy is code, not a model.** A deterministic engine checks the kill switch, the action's autonomy rung, its blast-radius tier, confidence, spend caps and rate limits before anything runs.
* **Credentials stay with the executor.** The component that talks to your tools is separate from the model and is the only part that can use a credential.

## Isolation between workspaces

Each workspace's data is isolated from every other workspace at more than one layer:

* **Every record carries its workspace id**, taken from your verified sign-in session — never from a request body or from model output.
* **Postgres row-level security is enabled and forced** on workspace tables, so the database itself refuses to return another workspace's rows.
* **Application code also filters by workspace** on every query, as a second, independent check.
* **Requests for another workspace's records return "not found"**, so ids cannot be probed.

## Identity and access

* **Sign-in is provided by Clerk**, a dedicated identity provider. The sign-in options available to your workspace are those configured for Hive's sign-in.
* **Roles are held by Hive.** Your identity provider says who you are; Hive's own member record decides what you can do. See [Roles and permissions](/admin/roles-and-permissions).
* **Sessions are visible to you.** **Settings → Account → Security** lists your active sessions, with sign-out per device.
* **Private by default.** Chats, workflows, agents and files belong to their creator until shared, and sharing one never shares the owner's connected accounts.

## Protecting connected accounts

* **Credentials are encrypted per workspace.** Connector and model secrets are sealed with AES-256-GCM using a key derived for each workspace, bound to that workspace's id, so one workspace's secret cannot be decrypted in another's context.
* **Secrets are never shown to the model and never logged.**
* **OAuth tokens for managed connectors are held by Hive's connector platform**, not in Hive's application tables.
* **New connections start read-only.** Each account's autonomy is **Read** until an admin raises it. See [Accounts and autonomy](/integrations/accounts-and-autonomy).

## Defending against manipulated content

Hive reads emails, documents, tickets and web pages written by people outside your business. Any of them could contain text trying to steer an AI. Hive assumes they might:

* **Untrusted content is marked as untrusted** in every prompt ("spotlighted"), and treated as data, never as instructions.
* **Knowledge keeps its trust level.** Facts carry a trust tier, and anything derived from a low-trust source stays low-trust.
* **Recipients must already be on record.** Hive will not send to an address or contact it has never seen in your systems.
* **The model has no general-purpose fetch or execute tool.** It can only use vetted, typed tools.
* **External MCP tools are pinned.** When you connect an MCP server, Hive records a fingerprint of each tool's name, description and input schema. A tool that changes later is not silently trusted. Every MCP tool is treated as high-risk and not read-only unless an operator decides otherwise. See [MCP servers](/integrations/mcp-servers).

## Approvals, receipts and undo

* **Approvals are bound to the exact action.** An approval covers the precise parameters that were reviewed and expires after 7 days. A changed action needs a new approval.
* **Every action leaves a receipt** in the [Audit log](/approvals/audit-log): what was noticed, what was planned, how it was decided and what happened.
* **Reversible actions can be undone** from the audit log.

## Stopping everything

The **kill switch** halts every autonomous action and approval in the workspace immediately, survives restarts and fails closed. Circuit breakers on action rate, spend and error rate trip automatically. See [Safety and control](/admin/safety-and-control).

## Signed webhooks

Every webhook Hive receives is signature-verified — from its payment processor, identity provider, connector platform and job queue, and from your own [incoming webhooks](/integrations/incoming-webhooks), which use HMAC-SHA256 signatures over the raw request body.

## What we do not claim

We would rather be precise than impressive. Hive does not currently publish third-party certifications or attestation reports. If your organisation needs a security questionnaire completed, [contact us](/help/support).

## Responsible disclosure / contact

If you believe you have found a security vulnerability in Hive, please report it privately through [Get support](/help/support), with enough detail for us to reproduce it. Please do not access other customers' data or disrupt the service while testing, and give us reasonable time to fix an issue before disclosing it publicly.

## Related

<CardGroup cols={2}>
  <Card title="Data protection" icon="database" href="/security/data-protection">
    Retention, deletion, sharing and analytics.
  </Card>

  <Card title="AI and models" icon="microchip" href="/security/ai-and-models">
    Which AI providers Hive uses and how.
  </Card>

  <Card title="Infrastructure" icon="server" href="/security/infrastructure">
    Hosting, regions and providers.
  </Card>

  <Card title="How Hive works" icon="diagram-project" href="/developers/how-hive-works">
    The architecture end to end.
  </Card>
</CardGroup>
