Security of your IT map, built in
Your IT map contains the detailed blueprint of your IT estate — it deserves more than generic vendor pledges. This page describes exactly what is in place today, starting with hosting in the European Union.
Hosting and sovereignty
UrbaHive is hosted on Vercel and Supabase, in European Union regions only: customer data is stored in the EU. For organizations with specific hosting requirements (HDS, SecNumCloud, defense, healthcare, public sector), an on-premise hosting option (Kubernetes / Docker) is available on the Enterprise plan.
Encryption and backups
- In transit: all connections are encrypted (TLS).
- At rest: databases and storage are encrypted by our hosting platforms.
- Backups: encrypted, retained 30 days, restore tested monthly.
Authentication and access
- Sign-in: e-mail and password, one-time code sent by e-mail, or magic link.
- Roles: four roles per organization — Owner, Editor, Member, Viewer. They apply to the whole organization.
- Separate workspaces: each organization is a distinct workspace; a user can belong to several organizations and switch between them.
- Off-boarding: a departing member is removed from the organization and what they owned is transferred.
Regulatory framework
- GDPR: UrbaHive is a French company, subject to the GDPR, and customer data is hosted in the European Union. You can delete your organization and your account yourself from the app.
- NIS2 / DORA: UrbaHive is not a compliance tool. Its repository (applications, servers, flows, vendors, owners), its impact analysis and its audit log provide the inventory and traceability these texts presuppose.
- HDS / SecNumCloud: for these needs, the answer is the on-premise hosting option of the Enterprise plan.
Audit log and traceability
Every creation, modification and deletion in the repository is recorded with before / after values, as is every call to the MCP connector. The log can be consulted in the app, with filters. To report a vulnerability, write to contact@urbahive.com.
AI and the MCP connector
- UrbaHive calls no AI model itself, and your data is not used to train models. The MCP connector only answers the AI client you choose to connect.
- Access tokens: personal, scoped to a single organization, read-only by default; write access is optional.
- Scope: 31 read tools, 39 write tools, no delete tool; 60 requests per minute per token.
- Traceability: every MCP call is written to the audit log.
Security FAQ
Is my data shared with third parties?
Your data is stored in the European Union with our two hosting providers, Vercel and Supabase, encrypted in transit and at rest; payments are processed by Stripe. It is not used to train AI models. Within your organization, access is governed by four roles: Owner, Editor, Member, Viewer.
Can I retrieve my data if I cancel?
Yes, anytime: the repository exports to UrbaHive JSON and to the ArchiMate exchange format (XML), and diagrams to PNG and PDF. Monthly plans can be cancelled at any time, and you can delete your organization and your account yourself from the app.
Does UrbaHive use AI on my data?
No. UrbaHive calls no AI model itself and your data is not used to train models. The MCP connector only answers the AI client you choose to connect (Claude, Cursor…), with a token scoped to a single organization, read-only by default, and every call is written to the audit log.
A specific security question?
Contact our team