Select another country or region to get content for your location.
Quick Links

    Trust is fundamental to how MAXHUB designs, manufactures, and operates its collaboration products.

    This page describes the independent assurance, regulatory frameworks, and technical safeguards that apply to MAXHUB hardware, software, and cloud services for our customers.

    Security, privacy, and regulatory compliance are audited by independent third parties, and continually improved.

    bg
    comma comma
    Customers Usually Ask Us:

    Why should we trust MAXHUB?


    We hold independent third-party audits and certifications from Ernst & Young, IOActive, BSI, and CEPREI.

    What exactly is protected, and how?


    Our hardware is built on Intel platforms with TPM 2.0, Secure Boot, BitLocker encryption, and signed firmware verification. Our cloud platform runs on Microsoft Azure with regional data residency for our customers and TLS 1.2 in transit. Our software stack has been independently penetration-tested.

    How do you handle product vulnerabilities and updates?


    We operate a secure development lifecycle, sign all firmware, run a coordinated vulnerability disclosure process, and provide security updates across each product's supported lifecycle. See the Product Security section below.

    What proof is available?


    ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certificates, a SOC 2 Type I report by Ernst & Young, a third-party security assessment by IOActive, GDPR documentation, a NIS 2 alignment statement, and per-product security whitepapers.

    What does this mean for our IT and compliance?


    MAXHUB documentation is structured to answer the questions in standard procurement frameworks: GDPR Article 28 sub-processor questions, NIS 2 supply-chain requirements, ISO 27001 supplier-due-diligence questionnaires, and public-sector tender criteria.

    How do we verify the claims on this page?


    Request the source documents below. Public certificates are available for verification by accredited body. Restricted-use audit reports are available under NDA.

    Independent Assurance and Regulatory Alignment

    pic

    NIS 2 Directive

    MAXHUB operates organisational measures aligned with the NIS 2 Directive (EU 2022/2555) as transposed into national law in the European member states. Our NIS 2 alignment statement covers governance, incident handling, supply-chain security...

    pic

    SOC 2 Type I

    Independent SOC 2 Type I report issued by Ernst & Young Hua Ming LLP, covering MAXHUB OS and MAXHUB Pivot Plus against the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Privacy. The full report is available to...

    pic

    IOActive Security Assessment

    Independent third-party security assessment of MAXHUB OS on the XBoard V7 platform, performed by IOActive — a globally recognised cybersecurity firm with over 25 years of experience and clients across the Global 500. The engagement...

    pic

    ISO/IEC 27001:2022

    The MAXHUB manufacturer entity, Guangzhou Shirui Electronics Co., Ltd., is certified to ISO/IEC 27001:2022 — the international standard for Information Security Management Systems — by CEPREI Certification Body. The certificate covers...

    Cloud Services and Data Residency

    Where is data hosted, and who operates the infrastructure?

    All MAXHUB data is stored exclusively on regional servers and never leaves the region. MAXHUB cloud services: MAXHUB OS, MAXHUB Pivot+ (device management), MAXHUB Share (wireless presentation cloud component), and MAXHUB MTR are deployed on Microsoft Azure.

    Three regional deployments are available globally. Regional isolation between deployments is enforced at the Azure platform level. No cross-region data transfer takes place as part of normal product operation.

    pic

    Germany, Europe

    Microsoft Azure

    pic

    US West, North America

    Microsoft Azure

    pic

    Singapore, Asia

    Microsoft Azure

    Who controls the data, and who has access?

    The customer is the sole data controller for data generated by the customer's deployed devices and stored in the customer's tenant. MAXHUB acts as the data processor under a Data Processing Agreement consistent with Article 28 of the GDPR. MAXHUB does not use customer data for its own purposes.

    MAXHUB engineering personnel do not have standing access to customer data. For example access to a customer's Pivot+ tenant or to data within it requires the customer's explicit authorisation and a user-granted permission, on a per-request basis. The customer remains in control of when access is granted, the scope of access granted, and when access is withdrawn.

    Infrastructure-level administrative access to the cloud environment is restricted to a defined set of authorised MAXHUB personnel under documented role-based access controls and multi-factor authentication. Access is logged, monitored, and reviewed periodically under our ISO/IEC 27001-certified Information Security Management System. The design of these controls is within the scope of our SOC 2 Type I report audited by Ernst & Young.

    For deployments where any vendor access to deployed devices is unacceptable under the customer's threat model, MAXHUB supports a fully offline / locally-managed deployment in which Pivot+ is not used at all. In this model, no MAXHUB personnel have any access to deployed devices, because no remote access path exists.

    Encryption

    In transit, communication between MAXHUB cloud services and clients is encrypted using TLS 1.2. At rest, sensitive data, including account credentials and email addresses, is additionally encrypted using AES/CBC/PKCS5.

    How Secure Are the Products Themselves?

    Beyond cloud security, enterprise and public-sector security reviews increasingly assess the security of the product itself: how it is designed and built, how firmware is updated, how vulnerabilities are handled, and how long it is supported. This section answers those questions for MAXHUB hardware and software.

    placeholder

    Secure Development Lifecycle

    MAXHUB develops products under a documented secure development lifecycle governed by our ISO/IEC 27001:2022-certified Information Security Management System. Security is considered at design, development, testing, and release stages, including threat modelling, security testing, and code review. For MAXHUB OS, this is supplemented by independent third-party security assessment. The IOActive assessment of MAXHUB OS on the XBoard V7 platform (see Section 2).

    Hardware Security

    pic

    MAXHUB OS

    Built on 12th Gen Intel Core platforms with firmware verified against the manufacturer's signed certificates, locked hardware debug ports, and protected UEFI BIOS System Management Mode. Security is anchored by TPM 2.0, UEFI Secure Boot, BitLocker full-disk encryption, Hypervisor-protected Code Integrity (HVCI), Credential Guard, and Kernel DMA Protection, on Windows 11 Pro Enterprise.

    pic

    MAXHUB Microsoft Teams Rooms

    Products come in two platform families, each with its own security model. Both are certified under the Microsoft Teams Rooms certification programme.

    pic

    Windows-based products

    (e.g. W70 video bar, XCore compute kits, V7 XBoard)

    Built on 12th Gen Intel Core platforms with firmware verified against the manufacturer's signed certificates, locked hardware debug ports, and protected UEFI BIOS System Management Mode. Security is anchored by TPM 2.0, UEFI Secure Boot, BitLocker full-disk encryption, Hypervisor-protected Code Integrity (HVCI), Credential Guard, and Kernel DMA Protection, on Windows 11 IoT Enterprise.

    pic

    Android-based products

    (V50 and V70 video bars)

    Built on the Microsoft Device Ecosystem Platform (MDEP) — Microsoft's secured, enterprise-grade Android platform for Teams devices, not a standard Android build. The V50 and V70 currently run Android 13, with a planned upgrade to Android 15. As MDEP devices, they provide Secure Boot to ensure only trusted software loads at startup, hardware-backed device attestation via Microsoft's PKI to verify device integrity before boot, and Microsoft Secure Pairing to prevent unauthorised network access. Device attestation allows applications to verify the security state of the device before enabling services, supporting a Zero Trust posture. The devices run as locked-down appliances, support Android-based encryption enforceable through Microsoft Intune compliance policies, and are managed and monitored through Teams Admin Center and Microsoft Intune.

    placeholder

    Firmware Updates and Signing

    MAXHUB supports two firmware update models, which customers choose between based on their security posture:

    • Cloud-managed — Pivot+ pushes signed firmware updates with administrator approval. Customer IT teams can stage, schedule, and roll back updates. The full network path is documented in the per-product security whitepaper.

    • USB / fully offline — firmware update packages applied via USB, suitable for air-gapped environments and high-assurance deployments.
    pic

    Software and Firmware Updates

    (Windows products)

    All firmware images are cryptographically signed, and update authenticity is verified against the manufacturer's signing certificate before installation. On Windows-based products (MTR, MAXHUB OS on V7), Secure Boot and TPM 2.0 measured boot protect the integrity of the boot chain.

    pic

    Software and Firmware Updates

    (Android products)

    Security and platform updates follow a two-channel model. Microsoft delivers operating-system and platform security updates directly to MDEP devices, reducing dependency on OEM-specific update cycles and the fragmentation that affected earlier Android Teams devices. MAXHUB delivers device-level firmware updates for the hardware and its components. Together, this keeps both the Microsoft-owned platform layer and the MAXHUB-owned hardware layer current.

    placeholder
    bg

    Vulnerability Management and Coordinated Disclosure

    MAXHUB operates a coordinated vulnerability disclosure process. Security researchers, customers, and partners can report a suspected vulnerability in a MAXHUB product or service to security@maxhub.com. Reports are acknowledged, triaged by severity, and remediated through our product security process under the ISO/IEC 27001 management system. We coordinate remediation timelines with the reporter and aim to handle disclosure responsibly.
    pic

    Product Lifecycle and Security Update Commitments

    MAXHUB provides security updates for supported products throughout their supported lifecycle. Support lifetimes and end-of-support dates are defined per product line so that customers can plan refresh cycles and demonstrate, in their own audits, that deployed devices remain within a supported and patched window.
    • Product Lifecycle and End-of-Support Policy: see document library (Policies)

    For the Microsoft-owned layers, MAXHUB recommends customers review Microsoft's own security documentation:
    • Microsoft Teams Rooms security documentation (Microsoft Learn).
    • Windows 11 IoT Enterprise security documentation (Microsoft Learn).
    MAXHUB-authored MTR security material — the MAXHUB Microsoft Teams Rooms Security Whitepaper — is available in the document library (Product Security Overviews).

    What this means for you:
    If your review covers product security and lifecycle (firmware, vulnerability handling, security design, supported lifetime), this section answers it directly. For MTR specifically, you get a clear split between what MAXHUB secures and what Microsoft secures, with links to both parties' documentation — so your security team can complete a full assessment without gaps.
    placeholder
    bg

    Our Partners

    The strongest answer to "why should we trust you" is independent validation. Our partners fall into three groups: the technology providers whose platforms our products are built on, the independent firms that assess and audit our security, and the bodies that certify our management systems.

    All

    Technology and ecosystem partners

    Independent security assessors

    Certification bodies

    pic

    Microsoft

    Microsoft Teams Rooms hardware partner. From standard Windows and Android MTR devices to the unique MAXHUB XBar W70 Kit which was the first Windows Teams-certified video bar.

    pic

    Intel

    Titanium Partner status, the highest tier in the Intel Partner Alliance. MAXHUB MTR compute modules are built on the 12th Gen Intel Core platform with signed firmware verification, locked debug ports, and protected UEFI BIOS system management mode.

    pic

    Microsoft Azure

    Cloud infrastructure provider for MAXHUB cloud services, with EU data residency for EU customers.

    pic

    IOActive

    Independent third-party security assessor for MAXHUB OS (founded 1998; Global 500 client base).

    pic

    Ernst & Young

    Big Four firm; independent auditor for the MAXHUB SOC 2 Type I report.

    pic

    BSI

    British Standards Institution; certification body for ISO/IEC 27701:2019 (Privacy Information Management System).

    pic

    CEPREI

    Accredited certification body for ISO/IEC 27001:2022 (Information Security Management System).

    placeholder
    bg

    Document Library

    All MAXHUB security and privacy documentation is available on request. Complete a short form and you will automatically download requested documents.
    Independent audit reports the SOC 2 Type I report and the IOActive assessment letter are subject to a non-disclosure agreement under the auditors' restricted-use terms.

    Certificates

    Reports

    Policies

    Security

    Privacy

    Data Act

    Statement

    Certifications

    Independent audit reports & assessments

    Policies

    Product security overviews

    Privacy documents

    Data Act

    Statement

    No documents found.
    placeholder
    bg

    Contact, Document Requests & Security Inquiries

    Whatever stage you are at — evaluating MAXHUB, running a security review, or reporting an issue — this is where to reach us.
    pic

    Request compliance documents

    Request any of the certifications, audit reports, policies, product security overviews, or privacy documents listed in the document library. Public documents are typically provided within one business day; NDA-gated audit reports within two business days of NDA signature.

    pic

    Contact the security team

    For security and trust enquiries — including questions about our certifications, cloud architecture, data residency, or product security — contact the MAXHUB security team.

    pic

    Submit a security questionnaire

    If your organisation uses a standard security questionnaire as part of supplier onboarding — such as the CAIQ (Cloud Security Alliance), the SIG (Shared Assessments), or your own vendor security assessment — send it to us and our team will complete and return it. Where your questions map to existing documentation, we will reference the relevant document to speed up your review.

    pic

    Report a vulnerability

    If you believe you have found a security vulnerability in a MAXHUB product or service, please report it to our security team. Include the affected product, model, firmware version, a description of the issue, and reproduction steps where possible. We acknowledge reports, triage by severity, and coordinate remediation under our ISO/IEC 27001 management system.

    pic

    EU Data Act Request

    Request access to product-generated data under the EU Data Act; standard data and public documents are made available directly, while trade secret-protected content is provided upon execution of a confidentiality agreement.

    scroll top
    After Sales Support
    Contact Sales
    DocumentDownload

    Submit Request Form

    Submit Request Form

    Submit Request Form

    * Product Category

    Submit Request Form

    * Product Category
    You can find your MAXHUB serial number on the back of your device or in Settings > About Device > Device Information.

    This site uses cookies to personalise your experience and analyse site traffic. By clicking ACCEPT or continuing to browse the site, you are agreeing to our use of cookies. See our Cookies and Privacy Policy here

    {$ title $}
    {$ description $}

    {$ text $}

    {$ title $}
    pic