Trust and Security at Homebase
Your small business runs on trust. We protect it with industry-grade security, privacy, and reliability practices.

Application Security
We build security into every stage of development, from coding to release. Our team protects the Homebase app and supporting systems by proactively finding and fixing vulnerabilities.
Security Operations
We prevent, detect, and respond to threats through continuous monitoring and rapid incident response. Our team safeguards Homebase’s platform, assets, and customer environments.
Corporate Security
We secure the hardware, software, and services that support our workforce. By protecting internal systems, we strengthen productivity and safeguard customer data.
Security Assurance
We lead audits, compliance reviews, and customer security initiatives to verify our practices. This work builds trust and demonstrates Homebase’s commitment to being a secure SaaS provider.

Application Security
- Vulnerability management and annual penetration testing
- Secure application design, code scanning, and coding practices
- Responsible disclosure program for security researchers
- Strong cloud security controls
- Two-factor authentication, SSO, password-less login, and RBAC
- Data encryption in transit and at rest
Security Operations
- 24/7 monitoring through SIEM platforms
- Endpoint protection with EDR solutions
- Structured incident detection and response processes
- Threat intelligence and proactive threat hunting
- Log analysis, auditing, and continuous monitoring
- Post-incident reviews to drive improvement


Corporate Security
- Strong identity and access management for employees
- Device management and endpoint protection
- Secure remote work practices
- Background checks, onboarding, and off boarding security
- Employee security awareness and training programs
- Regular reviews of internal systems and processes
Security Assurance
- Independent audits and assessments
- Policy and compliance reviews
- Risk assessments and control testing
- Legal oversight for regulatory and contractual requirements
- Vendor and third-party security evaluations
- Continuous monitoring of compliance posture
- Regular reporting to leadership and stakeholders

Let’s make work easier
Security is built into everything we do.
Trust Center
Our Trust Center is your place to learn about how we keep your data safe. You can find details about our security practices, privacy commitments, and compliance certifications.
Responsible Discourse Program
We encourage responsible reporting of security vulnerabilities to help us keep our systems and customers safe. Learn how to report an issue here.
Status Page
Our Status Page provides real-time updates on system performance and availability. Check it anytime for incident reports and maintenance updates.
Subprocessor
We work with trusted service providers to support our operations. You can view the list of our approved subprocessors here.
Privacy
We are committed to protecting your personal information and handling it with care. Learn more about our privacy practices here.
Contact Security Team
Our security team is here to help. If you have questions, concerns, or need to report a security issue, reach us directly here:
FAQ
Questions?
If you need help with a security questionnaire, please visit our Trust Center to connect with our security team or submit your questionnaire directly.
How do you ensure security in your software development lifecycle (SDLC)?
Homebase follows a secure SDLC, incorporating security, privacy, and compliance at every stage. This includes secure coding practices, peer reviews, regular testing, and automated tools for SAST and SCA in progress. New dependencies undergo formal review, and automated secret scanning prevents secrets from being committed to repositories.
How is data encrypted at rest and in transit?
Data at rest is encrypted using strong cryptographic algorithms, including AES-256 encryption and AWS KMS for database and bucket encryption. Data in transit is encrypted using strong cryptographic algorithms and TLS implementations.
Do you perform regular security assessments and penetration testing?
Yes, Homebase conducts annual penetration tests and monthly vulnerability scans.
How is AI used in Homebase products?
AI helps small businesses save time with smarter scheduling, shift reminders, and workforce insights. We design our AI features with security and privacy in mind, ensuring customer data is protected while delivering these benefits.
