Skip to content

Compliant by design.

Hive CPQ is built to meet the reg­u­la­tions and stan­dards your indus­try runs on, so your process­es stay audit-ready all year round.

Iso test png

ISO 27001 certified.

ISO 27001 is the international standard for information security, protecting your records against loss, unauthorised access and tampering. Kiwa, an independent security organisation, audits us every year and fully recertifies us every three years.

Download our certificate
Gdpr test png

GDPR compliant.

Hive CPQ meets every GDPR requirement, and we keep our data protection processes sharp and up to date. Because all data is stored in Europe, European privacy law applies automatically.

Download our DPA

Safe and sound.

Secu­ri­ty runs through every lay­er of Hive CPQ, from how your team logs in to how we test the platform.

Access controls.

  • Single Sign-On
    One secure login, using existing company credentials.

  • Multi-factor authentication
    Only verified users gain access to your environment.

  • Role-Based Access Control
    Users access only what their permissions allow.

Thorough testing.

  • Continuous security testing
    Regular testing finds risks before they reach you.

  • Regular updates and patches
    Continuous patches keep the platform secure and current.

  • Independent specialists
    External security experts check and strengthen our setup.

  • Yearly penetration testing
    OWASP-based pen tests find and fix vulnerabilities.

  • Intrusion detection and prevention
    These systems add an extra layer of protection.

Always on.

Hive CPQ is built for stability, with continuous monitoring and proactive maintenance that keep your environment live, 24/7.

  • 24/7 monitoring. We detect and respond to issues the moment they arise.

  • Seven days a week. Hive CPQ is available around the clock, every day of the week.

  • Live status page. 99.8% average uptime.

Check platform status in real-time

Ready for anything.

If some­thing does go wrong, we have the plan and the safe­guards to put it right fast.

Incident response.

  • We prioritize the fix, update the status and run a post-mortem.

Data loss prevention.

  • Active measures guard against accidental or malicious data leaks.

Frequent backups.

  • Regular backups mean quick data recovery if it is ever needed.

Maintenance.

  • We notify you in advance and log every change in our release notes.

Minimal disruption.

  • We deploy urgent fixes midweek, with minimal disruption.

Security training.

  • Our team receives regular training to stay current on best practices.

Frequently asked questions.

Detailed answers on security, privacy, compliance and reliability.

Still have questions? Reach us at info@hivecpq.com

How does authentication and multi-factor security work?

Hive CPQ uses SSO and mul­ti-fac­tor authen­ti­ca­tion, man­aged through Auth0, a reli­able part­ner that han­dles MFA and SSO across mul­ti­ple third-par­ty providers. 

As a man­u­fac­tur­er or admin, you cre­ate accounts and invite any­one who needs access to your envi­ron­ment. Role-Based Access Con­trol means each user only sees what you allow, and admin­is­tra­tive func­tions stay lim­it­ed to autho­rized admins.

What security testing do you perform on Hive CPQ?

We run auto­mat­ed and man­u­al secu­ri­ty test­ing inter­nal­ly, plus year­ly pen­e­tra­tion test­ing by an autho­rised third party.

Where can I find your security policy and standards?

Our appli­ca­tion secu­ri­ty approach is doc­u­ment­ed on our doc­u­men­ta­tion por­tal. Don’t have access yet? Request it.

How do you handle patches, especially security patches?

We update the plat­form with secu­ri­ty patch­es reg­u­lar­ly, dai­ly when need­ed. Planned main­te­nance hap­pens only at week­ends, and we always tell you in advance. Urgent fix­es can hap­pen mid­week, but we keep dis­rup­tion to a min­i­mum. You can check cur­rent sta­tus on our live sta­tus page.

How does Hive CPQ counter malware, spam, and malicious attacks?

We work only with sub­proces­sors and third-par­ty ven­dors — from email and host­ing to authen­ti­ca­tion and invoic­ing — that meet strict secu­ri­ty stan­dards and pro­to­cols, as required by our ISO 27001 certification.

How does Hive CPQ handle incidents that could affect service?

With 24/7 mon­i­tor­ing, we detect and respond the moment an issue aris­es. Auto­mat­ed alerts noti­fy our team, and depend­ing on the inci­dent, your ded­i­cat­ed Hive con­tact reach­es out to you. 

Our inci­dent response plan kicks in: we pri­or­i­tize the fix, keep the sta­tus page up to date, and run a post-mortem. Hive CPQ has an aver­age uptime of 99.8% and is avail­able sev­en days a week.

Do you have a disaster recovery plan?

Yes. Hive CPQ has a dis­as­ter recov­ery plan in place. We run reg­u­lar back­up and recov­ery tests, iden­ti­fy poten­tial risks proac­tive­ly, and fol­low clear pro­ce­dures in line with ISO 27001.

Where is my data stored and processed?

All data is stored with­in the Euro­pean Union, in our data cen­tre in Ger­many, on secure cloud servers that meet mod­ern secu­ri­ty stan­dards. Our head­quar­ters is in Bel­gium, so your envi­ron­ment is set up and man­aged from there.

What is your data retention policy?

You stay in con­trol of your data at all times. We retain it only while you active­ly use Hive CPQ. If you stop using the plat­form, we per­ma­nent­ly delete all your data. If you return lat­er, a full rein­stal­la­tion and set­up is required.

How is my data used to improve Hive CPQ?

We don’t use your data beyond what’s need­ed for imple­men­ta­tion or sup­port. You stay in con­trol and can ask how your data is used, or request its dele­tion, at any time. 

Want to help improve Hive CPQ? Sub­mit fea­ture requests, share feed­back with our con­sul­tants, or report bugs through our sup­port system.

What audits and controls are in place?

Hive CPQ is ISO 27001 cer­ti­fied. To main­tain cer­ti­fi­ca­tion, we under­go annu­al sur­veil­lance audits and a full recer­ti­fi­ca­tion every three years by inde­pen­dent secu­ri­ty orga­ni­za­tion Kiwa. You can down­load the cer­tifi­cate.

How do you keep customer data separated?

Each cus­tomer’s data is stored sep­a­rate­ly, so only the peo­ple you invite to your envi­ron­ment can access it, based on the roles you assign them.

How do you cover GDPR implications?

Our ISO 27001 cer­ti­fi­ca­tion also cov­ers GDPR. Because all our data is stored in Europe, Euro­pean reg­u­la­tions apply. You can con­tact us any­time to ask how your data is used, where it’s stored, or to request its deletion.

Hive logo

The right choice.

Excit­ed to see what your new CPQ can real­ly do? Explore the ins and outs of Hive CPQ in a 30-day free trial.