Frequently asked questions for security and privacy reviews.
Direct answers to the questions we hear most from security and privacy reviewers, each linking to the page that goes deeper. For operational detail, see the product documentation at docs.performancehub.co - the docs site is aware of the signed-in user and their access level, so additional documentation may be available depending on account type. If your question is not here, ask us directly (see Contact & vendor review).
Answers.
- Where does my data live?
- Performance Hub is edge-first, not edge-only. Agent state and supported processing live on the appliance, while the cloud platform holds account and user data, configuration, metadata, logs, synced data, and cloud-delivered services. Backups, footage and related stored data use the region you select per facility where regional storage controls apply. See Data ownership, residency & lifecycle.
- Can Performance Hub see my conversations or my footage?
- By default, Performance Hub can see operational telemetry, backup metadata and spend metering. It does not have a live feed of your conversations, and it does not store the content of your AI prompts or responses. Video access is role-gated, per-facility, and fully access-logged. At your request, for support or product-architecture work, you can grant Performance Hub temporary access through organisation settings and/or individual agent configuration. We may also work with you on site or via remote sessions for architecture advice and planning. See Data ownership.
- How do users authenticate, and is MFA available?
- Users authenticate via federated single sign-on (Google, Microsoft, Apple, Slack) or email-based login. Organisation policy can require additional Performance Hub multi-factor authentication, independent of MFA enforced by the identity provider. Authorisation is role-based and centrally enforced. See Security architecture.
- How does support access to an AI Agent work?
- At your request, for support or product-architecture work, access for Performance Hub staff and organisation administrators may be granted through organisation settings and/or individual agent configuration. We may also work with you on site or via remote sessions for architecture advice and planning. See Security architecture.
- How is multi-tenancy isolation enforced? Can we get a dedicated environment?
- On the standard cloud platform, isolation is enforced through centralised access control in a multi-tenant architecture. Eligible enterprise and government customers may run on a dedicated Performance Hub architecture, subject to contract. See Security architecture.
- Who is responsible for secrets and credentials placed on an AI Agent?
- Keys, passwords, tokens and other confidential material you place on an AI Agent - including through scripts, skills or workspace files - are under your control. Performance Hub encrypts and securely stores agent backups; exposure introduced by customer-configured agent behaviour is your responsibility. See Shared responsibility.
- Is my data used to train AI models?
- Performance Hub never trains on your data. When we call a third-party model on your behalf, we opt out of provider training and use non-training channels on every request; prompt and response content is never stored by the router. A provider's own terms ultimately govern their internal practices, so if a provider is not acceptable to you, you can disable it and restrict routing to the models you approve, including private or on-premise inference. See AI, models & responsible AI.
- Which AI models touch my data, and can I control that?
- You decide. Administrators control which models are enabled for the facility and can restrict individual agents further, including locking routing to only the providers you approve. For sensitive data, private or on-premise inference keeps it on site. See AI, models & responsible AI.
- How is facial recognition governed?
- It is opt-in per camera and uses mathematical face templates. Facial collections are isolated per facility by default; organisations may enable cross-facility access for multi-site deployments under their policy. Identification is a separate activity from recording, with its own controls. Blacklisting suppresses a face (the opt-out mechanism). Lawful operation - consent, signage, lawful basis - is the operator's responsibility. See Video, vision & facial recognition.
- Who can access my video, and is it logged?
- Management-level roles at your facility only, not standard end-user accounts, and never across facilities for footage. Guest access is via scoped, expiring links that exclude all people and AI data. Every viewing session, staff and guest, is access-logged. See Video, vision & facial recognition.
- What happens to my data if I leave?
- Removing a device factory-resets it and revokes its credentials immediately. Cloud backups are retained under your retention policy until they age out, then removed. Account and data deletion is available with identity verification. Some records are retained where the law requires. See Data ownership, residency & lifecycle.
- Can a partner or integration access my data without me knowing?
- No. External integrations are configured by you, scoped per facility, off by default, and can be disabled at any time. A partner cannot push data to, or act on, a facility that has not enabled them. API and MCP keys can never see more than their owner could in the UI. See Integrations, partners & data sharing.
- Who is responsible for what a partner does with my data?
- You and the partner. Performance Hub provides and vets the secure mechanism and enforces your per-facility enablement, but what a partner does with data once it is in their system is governed by your agreement with them. The same applies to any API or MCP integration you enable. See Shared responsibility.
- What certifications cover the platform?
- The infrastructure the platform runs on is independently certified. Performance Hub itself is not currently SOC 2 or ISO 27001 certified; these are the certified foundations it is built on. The current provider list, roles and certification sources live on one page so we do not maintain the same list in multiple places. See Sub-processors & infrastructure.
- Where do the platform's core services run?
- You choose where your stored data (backups and footage) resides per facility. Separately, the platform's core control-plane services run from a small number of core regions - Sydney, Singapore, London and the United States - and you are automatically routed to the nearest. Device connections are managed automatically, and content delivery uses a CDN where possible. See Data ownership, residency & lifecycle.
- Does Performance Hub claim your data stays in one country?
- No. The accurate claim is "customer-selectable storage regions with per-facility residency controls." Those controls apply to the stored data covered by each feature. Performance Hub's account, management and platform services span multiple jurisdictions, so we do not claim that all data stays on the appliance or in one country. See Data ownership, residency & lifecycle.