Skip to content
Solution

HiveMQ security and trust

Ensure safe and secure enterprise IoT deployments

We care about your data, so HiveMQ is designed from the ground up with maximum security in mind. Advanced security features are essential for mission-critical IoT scenarios, and HiveMQ gives you the flexibility to enable the specific security features that your individual use case requires.

Compliance at HiveMQ

HiveMQ is committed to using the highest information security and risk management standards to protect and handle customer data with the optimum level of trust and compliance.

GDPR

The collection and processing of personal data is made in accordance with relevant data protection regulations and safeguards for confidential information. Contact us for GDPR DPA and TOMs.

ISO/IEC 27001: 2022

The globally-recognized ISO/IEC 27001: 2022 certification signifies HiveMQ meets the high standard of excellence for information security management systems. Read more in our press release.

SOC 2 Type I

Being SOC 2 Type 1 certified ensures that our systems and controls are designed to meet rigorous security, availability, processing integrity, confidentiality, and privacy standards. Learn more from AICPA.

SOC 2 Type II

HiveMQ is now SOC 2 Type II compliant across all five trust criteria: security, availability, processing integrity, confidentiality, and privacy. Read more on our blog.

CSA STAR Registry

HiveMQ Cloud is listed on the Security, Trust, Assurance, and Risk (STAR) Registry which documents the security and privacy controls provided by cloud computing offerings.

TiSAX Compliance

HiveMQ is now TiSAX-compliant (Trusted Information Security Assessment Exchange), demonstrating our commitment to top-tier security standards for the automotive industry.

HiveMQ Platform core security features

Secure comms

Secure communication between HiveMQ and MQTT clients, and between HiveMQ cluster nodes.

Encryption

Native TLS/SSL support for increased performance, encryption at the transport layer vs. the application layer.

Authentication and authorization

Configurable via custom security extensions, from simple username/password to fine-grained RBAC.

Java key stores

Support for Java Key and Trust Stores, with dynamic loading at run time.

OCSP stapling

Allows an OCSP responder to determine the revocation status of an SSL certificate, reducing network traffic.

Tracing and logging

Configurable access log for MQTT clients, and audit log for Control Center actions.

HiveMQ security architecture

HiveMQ Security Architectural Overview

Security resources

Top recommended blogs and other resources to help you keep your IoT deployments secure.