HiveSkillUpSECURITY & ARCHITECTURE
TRUST & TRANSPARENCY

Security, Architecture
& Data Boundaries

Complete transparency about how HiveSkillUp handles deployment, data storage, access control and vendor boundaries. Self-hosted means your data stays in your environment.

DEPLOYMENT MODEL

Container-based Deployment

HiveSkillUp is delivered as a container-based application stack. It runs entirely within the customer's infrastructure. The customer controls all network boundaries, storage locations and access policies.

Deployment typeDocker container stack
InstallationOn customer-controlled servers
Infrastructure controlCustomer-managed network, storage, access
RuntimeFastAPI + React + MongoDB (containerized)
DATA BOUNDARIES

What stays where

Customer-controlled
All user accounts and credentials
Training progress and quiz results
Knowledge base content
Trade data (if exchange integration is used)
API keys (AES-256 encrypted, stored locally)
Audit trail entries
All configuration and firm settings
Vendor does NOT see
Production trading data
Individual trade decisions
Personal performance metrics
API keys or exchange credentials
Quiz answers or learning behavior
Chat messages between team members
UPDATE MODEL

How updates work

Updates are delivered as new container images. The customer controls when and how updates are applied. No permanent remote access by the vendor is required for daily operation.

FrequencyOccasional, planned releases
ApprovalCustomer decides when to apply
MethodContainer image update or supervised rollout
Vendor accessOnly upon explicit customer invitation
Daily operationNo continuous remote vendor operation required
ENCRYPTION & STORAGE

Security measures

API keysAES-256 (Fernet) encrypted at rest
Passwordsbcrypt hashed, never stored in plaintext
Audit trailSHA-256 hash chain (WORM — Write Once Read Many)
TransportHTTPS/TLS for all communications
SessionsJWT tokens with httpOnly secure cookies
ACCESS CONTROL

Role-based access

Traders see only their own workspace, learning progress and relevant tools. Admins see team-level insights for coaching and quality improvement — not individual surveillance. The vendor has no default access to any customer environment.

Firm AdminFull platform management, team settings, knowledge base CMS, reporting
TraderPersonal workspace, learning modules, pre-trade tools, own progress only
VendorNo default production access. Support only for installation and maintenance
EXCHANGE INTEGRATION

API permission boundaries

Exchange API integration is strictly read-only. No withdrawal or trading execution rights are accepted. Keys are stored AES-256 encrypted within the customer's own infrastructure. The vendor never sees or accesses these credentials.

Permission levelRead-only only — no withdrawal, no trading rights
StorageEncrypted within customer infrastructure
Connection modelFirm-admin controlled, not individual trader input
VerificationConnection test before storage, multiple verification methods
PurposeTrade overview and preparation insights, not surveillance
EXPLICIT BOUNDARIES

What HiveSkillUp does NOT do

Does not perform trade surveillance or market abuse detection
Does not monitor employee trading for disciplinary purposes
Does not create punitive rankings or deficiency scores
Does not export data to external vendor systems
Does not require permanent vendor access for daily operation
Does not execute trades or manage funds on behalf of users
Does not replace professional legal, tax or compliance advice
FREQUENTLY ASKED QUESTIONS

FAQ

Where is my data stored?
All data is stored within your infrastructure in the MongoDB instance that runs as part of the container stack. No data leaves your environment by default.
Can the vendor see my trading data?
No. The vendor has no default access to your production environment. Support access is only granted upon explicit customer invitation for specific maintenance tasks.
What happens during updates?
Updates are delivered as new container images. You decide when to apply them. Updates can be self-managed or vendor-assisted — the customer always controls the timing.
Are exchange API keys safe?
API keys are AES-256 encrypted at rest within your infrastructure. Only read-only permissions are accepted. The vendor never has access to your exchange credentials.
Is HiveSkillUp a trade surveillance system?
No. HiveSkillUp is an enablement platform for preparation, onboarding and knowledge execution. It does not perform trade surveillance, employee monitoring or market abuse detection.
Can traders be individually monitored?
No. The platform shows team-level readiness insights for coaching purposes. It is not designed for individual surveillance, punitive scoring or naming-and-shaming.
What compliance standards apply?
The audit trail uses SHA-256 hash chains (WORM principle) for internal traceability. This supports internal documentation requirements. HiveSkillUp itself is not a regulatory compliance tool.