Skip to content

Compliant by design.

Hive CPQ is built to meet the reg­u­la­tions and stand­ards your industry runs on, so your pro­cesses stay audit-ready all year round.

Iso test png

ISO 27001 certified.

ISO 27001 is the international standard for information security, protecting your records against loss, unauthorised access and tampering. Kiwa, an independent security organisation, audits us every year and fully recertifies us every three years.

Download our certificate
Gdpr test png

GDPR compliant.

Hive CPQ meets every GDPR requirement, and we keep our data protection processes sharp and up to date. Because all data is stored in Europe, European privacy law applies automatically.

Download our DPA

Safe and sound.

Secur­ity runs through every lay­er of Hive CPQ, from how your team logs in to how we test the platform.

Access controls.

  • Single Sign-On
    One secure login, using existing company credentials.

  • Multi-factor authentication
    Only verified users gain access to your environment.

  • Role-Based Access Control
    Users access only what their permissions allow.

Thorough testing.

  • Continuous security testing
    Regular testing finds risks before they reach you.

  • Regular updates and patches
    Continuous patches keep the platform secure and current.

  • Independent specialists
    External security experts check and strengthen our setup.

  • Yearly penetration testing
    OWASP-based pen tests find and fix vulnerabilities.

  • Intrusion detection and prevention
    These systems add an extra layer of protection.

Always on.

Hive CPQ is built for stability, with continuous monitoring and proactive maintenance that keep your environment live, 24/7.

  • 24/7 monitoring. We detect and respond to issues the moment they arise.

  • Seven days a week. Hive CPQ is available around the clock, every day of the week.

  • Live status page. 99.8% average uptime.

Check platform status in real-time

Ready for anything.

If some­thing does go wrong, we have the plan and the safe­guards to put it right fast.

Incident response.

  • We prioritize the fix, update the status and run a post-mortem.

Data loss prevention.

  • Active measures guard against accidental or malicious data leaks.

Frequent backups.

  • Regular backups mean quick data recovery if it is ever needed.

Maintenance.

  • We notify you in advance and log every change in our release notes.

Minimal disruption.

  • We deploy urgent fixes midweek, with minimal disruption.

Security training.

  • Our team receives regular training to stay current on best practices.

Frequently asked questions.

Detailed answers on security, privacy, compliance and reliability.

Still have questions? Reach us at info@hivecpq.com

How does authentication and multi-factor security work?

Hive CPQ uses SSO and multi-factor authen­tic­a­tion, man­aged through Auth0, a reli­able part­ner that handles MFA and SSO across mul­tiple third-party providers. 

As a man­u­fac­turer or admin, you cre­ate accounts and invite any­one who needs access to your envir­on­ment. Role-Based Access Con­trol means each user only sees what you allow, and admin­is­trat­ive func­tions stay lim­ited to author­ized admins.

What security testing do you perform on Hive CPQ?

We run auto­mated and manu­al secur­ity test­ing intern­ally, plus yearly pen­et­ra­tion test­ing by an author­ised third party.

Where can I find your security policy and standards?

Our applic­a­tion secur­ity approach is doc­u­mented on our doc­u­ment­a­tion portal. Don’t have access yet? Request it.

How do you handle patches, especially security patches?

We update the plat­form with secur­ity patches reg­u­larly, daily when needed. Planned main­ten­ance hap­pens only at week­ends, and we always tell you in advance. Urgent fixes can hap­pen mid­week, but we keep dis­rup­tion to a min­im­um. You can check cur­rent status on our live status page.

How does Hive CPQ counter malware, spam, and malicious attacks?

We work only with sub­pro­cessors and third-party vendors — from email and host­ing to authen­tic­a­tion and invoicing — that meet strict secur­ity stand­ards and pro­to­cols, as required by our ISO 27001 certification.

How does Hive CPQ handle incidents that could affect service?

With 24/7 mon­it­or­ing, we detect and respond the moment an issue arises. Auto­mated alerts noti­fy our team, and depend­ing on the incid­ent, your ded­ic­ated Hive con­tact reaches out to you. 

Our incid­ent response plan kicks in: we pri­or­it­ize the fix, keep the status page up to date, and run a post-mortem. Hive CPQ has an aver­age uptime of 99.8% and is avail­able sev­en days a week.

Do you have a disaster recovery plan?

Yes. Hive CPQ has a dis­aster recov­ery plan in place. We run reg­u­lar backup and recov­ery tests, identi­fy poten­tial risks pro­act­ively, and fol­low clear pro­ced­ures in line with ISO 27001.

Where is my data stored and processed?

All data is stored with­in the European Uni­on, in our data centre in Ger­many, on secure cloud serv­ers that meet mod­ern secur­ity stand­ards. Our headquar­ters is in Bel­gi­um, so your envir­on­ment is set up and man­aged from there.

What is your data retention policy?

You stay in con­trol of your data at all times. We retain it only while you act­ively use Hive CPQ. If you stop using the plat­form, we per­man­ently delete all your data. If you return later, a full rein­stall­a­tion and setup is required.

How is my data used to improve Hive CPQ?

We don’t use your data bey­ond what’s needed for imple­ment­a­tion or sup­port. You stay in con­trol and can ask how your data is used, or request its dele­tion, at any time. 

Want to help improve Hive CPQ? Sub­mit fea­ture requests, share feed­back with our con­sult­ants, or report bugs through our sup­port system.

What audits and controls are in place?

Hive CPQ is ISO 27001 cer­ti­fied. To main­tain cer­ti­fic­a­tion, we under­go annu­al sur­veil­lance audits and a full recer­ti­fic­a­tion every three years by inde­pend­ent secur­ity organ­iz­a­tion Kiwa. You can down­load the cer­ti­fic­ate.

How do you keep customer data separated?

Each cus­tom­er­’s data is stored sep­ar­ately, so only the people you invite to your envir­on­ment can access it, based on the roles you assign them.

How do you cover GDPR implications?

Our ISO 27001 cer­ti­fic­a­tion also cov­ers GDPR. Because all our data is stored in Europe, European reg­u­la­tions apply. You can con­tact us any­time to ask how your data is used, where it’s stored, or to request its deletion.

Hive logo

The right choice.

Excited to see what your new CPQ can really do? Explore the ins and outs of Hive CPQ in a 30-day free trial.