Security & privacy

Your data, isolated.

Demohub handles sensitive business information: brand contacts, certificates of insurance, demo schedules, financial records. Here's how we protect it.

Foundations

End-to-end encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Every page is HTTPS via Cloudflare with HSTS preloading.

Strict tenant isolation

Multi-tenant database with retailer-scoped access controls. Retailer A cannot read retailer B's data, even via API leaks.

No passwords

Magic-link authentication only. No passwords to leak, phish, or reuse from other breached sites.

Privacy-respecting analytics

Session replay enabled with PII masking. Email addresses, file uploads, and document URLs never leave your browser unmasked.

Privacy commitments

Infrastructure

We use industry-standard infrastructure to host your data and run the service:

See our full subprocessor list for details.

Compliance roadmap

We're a young company building toward enterprise-grade security:

If your organization requires specific compliance documents (DPA, security questionnaire, SCCs), contact david@demohubhq.com.

Responsible disclosure

Found a security issue? We'd like to hear from you. Email david@demohubhq.com with details. We respond within 24 hours, will not pursue legal action against good-faith researchers, and will credit reporters who request it.

Questions?

Privacy: david@demohubhq.com
Security: david@demohubhq.com
Compliance docs (DPA, SCCs): legal@demohubhq.com