Security & Data Protection
Skkrum is designed as a server-side collaboration platform. It is not an end-to-end encrypted messaging service. Hubroot uses a layered security approach intended to protect account information, communications, files, projects, and service infrastructure.
Our Security Approach
Encrypted transmission between supported clients and Skkrum services using secure network protocols.
Encryption at rest for service data in supported production storage environments.
Secure password hashing and authentication controls.
Role-based and least-privilege access controls for administrative and production systems.
Restricted internal access to user content based on operational need.
Security and access logging designed to support monitoring and incident investigation.
Backups and recovery measures appropriate to the service architecture.
Security patching, dependency management, and vulnerability remediation as part of ongoing operations.
Vendor and subprocessor review appropriate to the data and service provided.
Incident-response procedures for suspected security events.
Private Messages
Skkrum workspace owners and administrators are not provided a general feature that allows them to read users' private one-to-one messages. Because Skkrum is server-side rather than end-to-end encrypted, authorized Hubroot personnel may technically access content only in limited circumstances such as necessary support, security investigation, abuse prevention, legal compliance, or protection of rights and safety.
Responsible Security Reporting
If you believe you have discovered a security vulnerability affecting Skkrum, please report it through the security or support contact published on skkrum.com. Do not exploit a vulnerability, access other users' data, disrupt the Service, or publicly disclose sensitive details before Hubroot has had a reasonable opportunity to investigate and remediate the issue.