Information Security

Information Security at Hive

Hive is committed to ensuring that we conduct our activities in a way that information is safeguarded from potential security threats. In support of this, we have aligned our approach to information security with the ISO27001 framework.

FAQs



ISO 27001:2022 logo As part of our ISO 27001:2022 certification we engage with auditors annually to ensure compliance with the standard. We also engage with an external party to undertake annual penetration testing.

As part of our ISO/IEC 27001:2022 certified Information Security Management System, HiveHR maintains a comprehensive suite of security and compliance policies covering key operational areas:  

  • Core Security & Access Management: Includes the Information Security Policy, Acceptable Use Policy, Access Control Policy, Password Policy, and Physical Security & Clear Desk Policies.  
  • Device, Working Practice & Modern Technology: Includes the BYOD Policy, Mobile Device, Teleworking & Working Abroad Policy (HiveRoam), and AI Use Policy.  
  • Data Protection & Infrastructure: Includes the Data Management Policy, Cryptographic Controls Policy, Backup Policy, Network & Firewall Configuration Policy, and Secure Development Policy.  
  • Risk, Incident & Supplier Governance: Includes the GDPR Breach & Information Security Incident Management Policy, Business Continuity & Disaster Recovery Policy, Business Risk Policy, and Supplier Relationship Policy.

HiveHR utilises a multi-layered security framework aligned with ISO/IEC 27001:2022 and UK GDPR to safeguard data. Information is protected using AES 256 encryption at rest and TLS 1.2 or higher for transit, hosted within secure AWS infrastructure. Digital safeguards include Role-Based Access Control (RBAC) following least privilege principles, multi-factor authentication (MFA), and mandatory password management. Security is maintained across the data lifecycle through classification, automated backups, endpoint protection, and physical controls such as clear desk practices and restricted office access.

The data is stored and backed up in Dublin, Ireland.

Hive provides a range of methods that allow users to sign in to the platform. Available methods are:

  • Single Sign-On (SSO) using Google or Microsoft work accounts. Access can be restricted to approved email domains via domain whitelisting.
  • Magic Links: single-use, time-limited links sent to the user’s email address.
  • Passkeys: device-bound credentials.
  • Email and password, with the option for the customer to enforce two-factor authentication for all users. Two-factor authentication is performed using a one-time code generated by a third-party authenticator application. Recovery codes are provided to users at the point of setup, which can be downloaded and used to regain access if the authenticator application is unavailable.
  • SAML Single Sign-On: integration with the customer’s identity provider (such as Microsoft Entra, or Google Workspace)

Hive has processes in place to support customers if their employees exercise any of their privacy rights, such as the right of access.

We provide customers with a range of options to keep their employee information up to date. These include:

  • Self-service administration
  • Integration with employee records systems via Kombo, so that changes in personnel are automatically updated within Hive.
  • Secure file transfer of employee data files, such as via Zivver.

Hive uses one essential sub-processors outside the EU and has ensured contracts include Data Processing Agreements and encompass appropriate EU approved Standard Contractual Clauses.

This sub-processor, who is based in the USA,is responsible for the delivery of emails as part of the surveying aspect of Hive. To email individuals a unique link to a survey they process the first name and email address.

When planning to use any third parties, risk assessments are carried out to ensure there’s an adequate level of security and data protection in place, such as checking security certifications, ensuring Data Protection Agreements or EU approved Standard Contractual Clauses are in place.

Information Security Statement

We have developed this Information Security Statement to provide our employees and customers with assurances about the way we receive, store, and process information. This statement forms part of our Information Security Management System (ISMS) and is based on the ISO/IEC 27001:2022 Standard. Our Statement of Applicability details the controls that are relevant to our organisation and how we address risks in each of those areas.

Information is at the heart of our business, and any threat to its confidentiality, integrity, or availability is a direct threat to our business. Information security concepts apply to, and are the responsibility of, all our employees. Hive’s Senior Leadership Team is fully supportive of the need for, and enforcement of, information security policies, procedures and Hive’s ISMS. The Information Security & Compliance Manager is responsible for the management and maintenance of the ISMS.

The Senior Leadership Team is committed to ensuring that we conduct our activities in such a way that information is adequately safeguarded from potential security threats and this statement has been approved by the CEO to ensure that all information assets (information in all its forms) are protected and are used in the best interests of the company and its clients, within applicable laws and regulations, and as part of our contractual agreements. Each year we set information security objectives and measure and report on adherence to these objectives throughout the year in various internal forums. It is essential that we all understand the importance of information security, our responsibilities, and the consequences of ignoring them, and ultimately the effects of security on our success, and that we all recognise and understand our role in protecting our information assets. We identify risks and opportunities that are relevant to our organisation, and document, assess, plan, and treat them as necessary, always with the objective of continual improvement in mind. 

The Information Security Manual will help you understand your role in delivering this aspect of our organisations risk management activities. It will also help us continually improve the security of our information assets.

If there is anything within this statement you do not understand, please speak with the Information Security & Compliance Manager who will be able to advise you.

John Ryder – CEO & Founder