Select your country or region
Trust is fundamental to how MAXHUB designs, manufactures, and operates its collaboration products.
This page describes the independent assurance, regulatory frameworks, and technical safeguards that apply to MAXHUB hardware, software, and cloud services for our customers.
Security, privacy, and regulatory compliance are audited by independent third parties, and continually improved.
MAXHUB operates organisational measures aligned with the NIS 2 Directive (EU 2022/2555) as transposed into national law in the European member states. Our NIS 2 alignment statement covers governance, incident handling, supply-chain security...
Independent SOC 2 Type I report issued by Ernst & Young Hua Ming LLP, covering MAXHUB OS and MAXHUB Pivot Plus against the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Privacy. The full report is available to...
Independent third-party security assessment of MAXHUB OS on the XBoard V7 platform, performed by IOActive — a globally recognised cybersecurity firm with over 25 years of experience and clients across the Global 500. The engagement...
The MAXHUB manufacturer entity, Guangzhou Shirui Electronics Co., Ltd., is certified to ISO/IEC 27001:2022 — the international standard for Information Security Management Systems — by CEPREI Certification Body. The certificate covers...
All MAXHUB data is stored exclusively on regional servers and never leaves the region. MAXHUB cloud services: MAXHUB OS, MAXHUB Pivot+ (device management), MAXHUB Share (wireless presentation cloud component), and MAXHUB MTR are deployed on Microsoft Azure.
Three regional deployments are available globally. Regional isolation between deployments is enforced at the Azure platform level. No cross-region data transfer takes place as part of normal product operation.
Germany, Europe
US West, North America
Singapore, Asia
The customer is the sole data controller for data generated by the customer's deployed devices and stored in the customer's tenant. MAXHUB acts as the data processor under a Data Processing Agreement consistent with Article 28 of the GDPR. MAXHUB does not use customer data for its own purposes.
MAXHUB engineering personnel do not have standing access to customer data. For example access to a customer's Pivot+ tenant or to data within it requires the customer's explicit authorisation and a user-granted permission, on a per-request basis. The customer remains in control of when access is granted, the scope of access granted, and when access is withdrawn.
Infrastructure-level administrative access to the cloud environment is restricted to a defined set of authorised MAXHUB personnel under documented role-based access controls and multi-factor authentication. Access is logged, monitored, and reviewed periodically under our ISO/IEC 27001-certified Information Security Management System. The design of these controls is within the scope of our SOC 2 Type I report audited by Ernst & Young.
For deployments where any vendor access to deployed devices is unacceptable under the customer's threat model, MAXHUB supports a fully offline / locally-managed deployment in which Pivot+ is not used at all. In this model, no MAXHUB personnel have any access to deployed devices, because no remote access path exists.
Encryption
In transit, communication between MAXHUB cloud services and clients is encrypted using TLS 1.2. At rest, sensitive data, including account credentials and email addresses, is additionally encrypted using AES/CBC/PKCS5.
Beyond cloud security, enterprise and public-sector security reviews increasingly assess the security of the product itself: how it is designed and built, how firmware is updated, how vulnerabilities are handled, and how long it is supported. This section answers those questions for MAXHUB hardware and software.
Built on 12th Gen Intel Core platforms with firmware verified against the manufacturer's signed certificates, locked hardware debug ports, and protected UEFI BIOS System Management Mode. Security is anchored by TPM 2.0, UEFI Secure Boot, BitLocker full-disk encryption, Hypervisor-protected Code Integrity (HVCI), Credential Guard, and Kernel DMA Protection, on Windows 11 Pro Enterprise.
Products come in two platform families, each with its own security model. Both are certified under the Microsoft Teams Rooms certification programme.
(e.g. W70 video bar, XCore compute kits, V7 XBoard)
Built on 12th Gen Intel Core platforms with firmware verified against the manufacturer's signed certificates, locked hardware debug ports, and protected UEFI BIOS System Management Mode. Security is anchored by TPM 2.0, UEFI Secure Boot, BitLocker full-disk encryption, Hypervisor-protected Code Integrity (HVCI), Credential Guard, and Kernel DMA Protection, on Windows 11 IoT Enterprise.
(V50 and V70 video bars)
Built on the Microsoft Device Ecosystem Platform (MDEP) — Microsoft's secured, enterprise-grade Android platform for Teams devices, not a standard Android build. The V50 and V70 currently run Android 13, with a planned upgrade to Android 15. As MDEP devices, they provide Secure Boot to ensure only trusted software loads at startup, hardware-backed device attestation via Microsoft's PKI to verify device integrity before boot, and Microsoft Secure Pairing to prevent unauthorised network access. Device attestation allows applications to verify the security state of the device before enabling services, supporting a Zero Trust posture. The devices run as locked-down appliances, support Android-based encryption enforceable through Microsoft Intune compliance policies, and are managed and monitored through Teams Admin Center and Microsoft Intune.
(Windows products)
All firmware images are cryptographically signed, and update authenticity is verified against the manufacturer's signing certificate before installation. On Windows-based products (MTR, MAXHUB OS on V7), Secure Boot and TPM 2.0 measured boot protect the integrity of the boot chain.
(Android products)
Security and platform updates follow a two-channel model. Microsoft delivers operating-system and platform security updates directly to MDEP devices, reducing dependency on OEM-specific update cycles and the fragmentation that affected earlier Android Teams devices. MAXHUB delivers device-level firmware updates for the hardware and its components. Together, this keeps both the Microsoft-owned platform layer and the MAXHUB-owned hardware layer current.
All
Technology and ecosystem partners
Independent security assessors
Certification bodies
Microsoft Teams Rooms hardware partner. From standard Windows and Android MTR devices to the unique MAXHUB XBar W70 Kit which was the first Windows Teams-certified video bar.
Titanium Partner status, the highest tier in the Intel Partner Alliance. MAXHUB MTR compute modules are built on the 12th Gen Intel Core platform with signed firmware verification, locked debug ports, and protected UEFI BIOS system management mode.
Cloud infrastructure provider for MAXHUB cloud services, with EU data residency for EU customers.
Independent third-party security assessor for MAXHUB OS (founded 1998; Global 500 client base).
Big Four firm; independent auditor for the MAXHUB SOC 2 Type I report.
British Standards Institution; certification body for ISO/IEC 27701:2019 (Privacy Information Management System).
Accredited certification body for ISO/IEC 27001:2022 (Information Security Management System).
Certificates
Reports
Policies
Security
Privacy
Data Act
Statement

Request any of the certifications, audit reports, policies, product security overviews, or privacy documents listed in the document library. Public documents are typically provided within one business day; NDA-gated audit reports within two business days of NDA signature.

For security and trust enquiries — including questions about our certifications, cloud architecture, data residency, or product security — contact the MAXHUB security team.

If your organisation uses a standard security questionnaire as part of supplier onboarding — such as the CAIQ (Cloud Security Alliance), the SIG (Shared Assessments), or your own vendor security assessment — send it to us and our team will complete and return it. Where your questions map to existing documentation, we will reference the relevant document to speed up your review.

If you believe you have found a security vulnerability in a MAXHUB product or service, please report it to our security team. Include the affected product, model, firmware version, a description of the issue, and reproduction steps where possible. We acknowledge reports, triage by severity, and coordinate remediation under our ISO/IEC 27001 management system.

Request access to product-generated data under the EU Data Act; standard data and public documents are made available directly, while trade secret-protected content is provided upon execution of a confidentiality agreement.
This site uses cookies to personalise your experience and analyse site traffic. By clicking ACCEPT or continuing to browse the site, you are agreeing to our use of cookies. See our Cookies and Privacy Policy here
{$ text $}