Legal and Trust

OneHub Security Policy

Last updated: July 20, 2026

Purpose

At OneHub, security is a core design principle. Our platform is designed with a local-first architecture wherever practical, allowing users to retain control of their data while providing secure access to AI providers, plugins, browser automation, and cloud services when requested.

This Security Policy describes the measures we take to protect customer information and the shared responsibilities between OneHub and our users.

Security Principles

Our security program is built around the following principles:

  • Least privilege
  • Defense in depth
  • Secure by default
  • Local-first data processing where possible
  • Encryption of data in transit
  • Continuous improvement

Local-First Architecture

Whenever practical:

  • Projects remain on the user's device.

Prompt history remains local.

Uploaded files remain local until the user explicitly sends them to an external service.

API keys are stored locally whenever supported.

Cloud processing only occurs when a user enables cloud-connected features or sends requests to third-party AI providers.

Encryption

We use industry-standard encryption practices where applicable.

Data in Transit

Communications between OneHub services and supported cloud services use HTTPS/TLS.

Data at Rest

Where OneHub stores customer information on its own infrastructure, reasonable safeguards are used to protect stored data.

Users remain responsible for securing data stored on their own devices.

Authentication

Where accounts are required, OneHub supports secure authentication mechanisms.

Customers are responsible for:

  • choosing strong passwords
  • enabling multi-factor authentication where available

protecting account credentials.

API Keys

OneHub supports Bring Your Own API Key (BYOK).

Where technically feasible:

  • API keys are stored locally.

Keys are not intentionally transmitted to OneHub servers.

Keys are only used to authenticate requests to the provider selected by the user.

Customers are responsible for monitoring usage and costs associated with their API keys.

Third-Party AI Providers

OneHub integrates with third-party AI providers.

When a user submits prompts or files to a provider, that information is processed under the provider's own privacy policy and terms.

OneHub does not control how third-party providers store, retain, or process customer data.

Browser Automation

Browser automation executes actions authorized by the user.

Users are responsible for ensuring that automated actions comply with applicable laws and the terms of the websites they interact with.

Plugins and Integrations

Plugins, MCP servers, and integrations may request access to customer data.

Users should install only trusted plugins and review requested permissions before enabling them.

Software Updates

OneHub regularly releases:

  • bug fixes
  • security patches
  • performance improvements

compatibility updates.

Customers are encouraged to keep the software up to date.

Vulnerability Reporting

If you believe you have discovered a security vulnerability in OneHub, please report it responsibly.

Please include:

  • a description of the issue
  • reproduction steps
  • affected version(s)

proof of concept where appropriate.

Do not publicly disclose vulnerabilities until they have been investigated and, where appropriate, remediated.

Incident Response

If OneHub becomes aware of a confirmed security incident affecting customer data under our control, we will investigate promptly and, where required by law, notify affected customers within a reasonable timeframe.

Customer Responsibilities

Customers are responsible for:

  • securing their own devices
  • maintaining backups
  • protecting API keys and credentials
  • reviewing AI-generated output before use

complying with applicable laws and third-party service terms.

Contact

Security reports and questions may be directed to:

  • OneHub Security Team
  • Email: security@onehub.design
  • Website: https://onehub.design