Trust is fundamental to how MAXHUB designs, manufactures, and operates its collaboration products.
This page describes the independent assurance, regulatory frameworks, and technical safeguards that apply to MAXHUB hardware, software, and cloud services for our customers.
Security, privacy, and regulatory compliance are audited by independent third parties, and continually improved.
Independent Assurance and Regulatory Alignment
Cloud Services and Data Residency
Where is data hosted, and who operates the infrastructure?
All MAXHUB data is stored exclusively on regional servers and never leaves the region. MAXHUB cloud services: MAXHUB OS, MAXHUB Pivot+ (device management), MAXHUB Share (wireless presentation cloud component), and MAXHUB MTR are deployed on Microsoft Azure.
Three regional deployments are available globally. Regional isolation between deployments is enforced at the Azure platform level. No cross-region data transfer takes place as part of normal product operation.
Who controls the data, and who has access?
The customer is the sole data controller for data generated by the customer's deployed devices and stored in the customer's tenant. MAXHUB acts as the data processor under a Data Processing Agreement consistent with Article 28 of the GDPR. MAXHUB does not use customer data for its own purposes.
MAXHUB engineering personnel do not have standing access to customer data. For example access to a customer's Pivot+ tenant or to data within it requires the customer's explicit authorisation and a user-granted permission, on a per-request basis. The customer remains in control of when access is granted, the scope of access granted, and when access is withdrawn.
Infrastructure-level administrative access to the cloud environment is restricted to a defined set of authorised MAXHUB personnel under documented role-based access controls and multi-factor authentication. Access is logged, monitored, and reviewed periodically under our ISO/IEC 27001-certified Information Security Management System. The design of these controls is within the scope of our SOC 2 Type I report audited by Ernst & Young.
For deployments where any vendor access to deployed devices is unacceptable under the customer's threat model, MAXHUB supports a fully offline / locally-managed deployment in which Pivot+ is not used at all. In this model, no MAXHUB personnel have any access to deployed devices, because no remote access path exists.
Encryption
In transit, communication between MAXHUB cloud services and clients is encrypted using TLS 1.2. At rest, sensitive data, including account credentials and email addresses, is additionally encrypted using AES/CBC/PKCS5.
How Secure Are the Products Themselves?
Beyond cloud security, enterprise and public-sector security reviews increasingly assess the security of the product itself: how it is designed and built, how firmware is updated, how vulnerabilities are handled, and how long it is supported. This section answers those questions for MAXHUB hardware and software.
Hardware Security
Product Lifecycle and Security Update Commitments
- Product Lifecycle and End-of-Support Policy: see document library (Policies)
- Microsoft Teams Rooms security documentation (Microsoft Learn).
- Windows 11 IoT Enterprise security documentation (Microsoft Learn).
If your review covers product security and lifecycle (firmware, vulnerability handling, security design, supported lifetime), this section answers it directly. For MTR specifically, you get a clear split between what MAXHUB secures and what Microsoft secures, with links to both parties' documentation — so your security team can complete a full assessment without gaps.
All
Technology and ecosystem partners
Independent security assessors
Certification bodies
Certificates
Reports
Policies
Security
Privacy
Data Act
Statement




