Purpose
At OneHub, security is a core design principle. Our platform is designed with a local-first architecture wherever practical, allowing users to retain control of their data while providing secure access to AI providers, plugins, browser automation, and cloud services when requested.
This Security Policy describes the measures we take to protect customer information and the shared responsibilities between OneHub and our users.
Security Principles
Our security program is built around the following principles:
- Least privilege
- Defense in depth
- Secure by default
- Local-first data processing where possible
- Encryption of data in transit
- Continuous improvement
Local-First Architecture
Whenever practical:
- Projects remain on the user's device.
Prompt history remains local.
Uploaded files remain local until the user explicitly sends them to an external service.
API keys are stored locally whenever supported.
Cloud processing only occurs when a user enables cloud-connected features or sends requests to third-party AI providers.
Encryption
We use industry-standard encryption practices where applicable.
Data in Transit
Communications between OneHub services and supported cloud services use HTTPS/TLS.
Data at Rest
Where OneHub stores customer information on its own infrastructure, reasonable safeguards are used to protect stored data.
Users remain responsible for securing data stored on their own devices.
Authentication
Where accounts are required, OneHub supports secure authentication mechanisms.
Customers are responsible for:
- choosing strong passwords
- enabling multi-factor authentication where available
protecting account credentials.
API Keys
OneHub supports Bring Your Own API Key (BYOK).
Where technically feasible:
- API keys are stored locally.
Keys are not intentionally transmitted to OneHub servers.
Keys are only used to authenticate requests to the provider selected by the user.
Customers are responsible for monitoring usage and costs associated with their API keys.
Third-Party AI Providers
OneHub integrates with third-party AI providers.
When a user submits prompts or files to a provider, that information is processed under the provider's own privacy policy and terms.
OneHub does not control how third-party providers store, retain, or process customer data.
Browser Automation
Browser automation executes actions authorized by the user.
Users are responsible for ensuring that automated actions comply with applicable laws and the terms of the websites they interact with.
Plugins and Integrations
Plugins, MCP servers, and integrations may request access to customer data.
Users should install only trusted plugins and review requested permissions before enabling them.
Software Updates
OneHub regularly releases:
- bug fixes
- security patches
- performance improvements
compatibility updates.
Customers are encouraged to keep the software up to date.
Vulnerability Reporting
If you believe you have discovered a security vulnerability in OneHub, please report it responsibly.
Please include:
- a description of the issue
- reproduction steps
- affected version(s)
proof of concept where appropriate.
Do not publicly disclose vulnerabilities until they have been investigated and, where appropriate, remediated.
Incident Response
If OneHub becomes aware of a confirmed security incident affecting customer data under our control, we will investigate promptly and, where required by law, notify affected customers within a reasonable timeframe.
Customer Responsibilities
Customers are responsible for:
- securing their own devices
- maintaining backups
- protecting API keys and credentials
- reviewing AI-generated output before use
complying with applicable laws and third-party service terms.
Contact
Security reports and questions may be directed to:
- OneHub Security Team
- Email: security@onehub.design
- Website: https://onehub.design