Security and trust

Where your data lives, who can see it, and what your IT team will ask us.

Hives.co is a Swedish company. Customer data is hosted in the EU by default, the platform is built GDPR-first, and single sign-on for Microsoft and Google is on every plan. This page answers the questions legal and IT usually send before a pilot, in plain language.

  • EU

    Customer data hosted in the EU by default

  • Sweden

    Swedish company, offices in Stockholm and Amsterdam

  • GDPR-first

    Built for European data protection, with a data processing agreement as part of the contract

  • SSO

    Microsoft and Google single sign-on on every plan, one-time passcodes for everyone else

  • 0 installs

    A web app: nothing to deploy, no client to roll out

  • Scoped

    Every collection has its own access scope, so a sensitive challenge stays with the named group

Where is our data hosted?

In the EU, by default. Hives.co is a Swedish company under EU law, and customer data stays in Europe unless you ask us for something else in writing. That is usually the shortest answer a legal team is hoping for, and it is the one we give.

Ask, and you get the hosting provider, the region and the current list of sub-processors in writing. We would rather send you the exact document than summarise it on a marketing page.

Who can sign in, and how?

Single sign-on for Microsoft and Google is included on every plan, Core included. People who already have a company account use it, so there is no new password to manage and access ends when their account does.

People without SSO sign in with a one-time passcode sent to their email, so there are no stored passwords to leak. And the people you most want to hear from, on the shop floor or in the store, do not need an account at all: a QR code by the line or a link in Teams lets them contribute from their own phone in about two minutes.

Inside the platform, every collection has its own scope. A sensitive challenge can be limited to a named group, a whole-company campaign can be open to everyone, and the two can run side by side.

What does GDPR-first mean in practice?

It means we built the platform for European rules rather than adapting to them afterwards. A data processing agreement is part of the contract, not an add-on you have to ask for. You decide what is collected: names can be attached to ideas, or a collection can accept anonymous contributions where that is what the works council or the union prefers.

It also means transparency for the people who contribute. Everyone can see what happened to their idea, which is both good data protection practice and the reason people keep contributing. We are used to questions from works councils, Betriebsräte, CSEs and Swedish unions; bring them to the first call and we answer them there.

What does IT have to deploy?

Nothing. Hives.co is a web app, so IT reviews access and identity rather than running a rollout. The Microsoft Teams and Google Workspace connections mean people contribute where they already work, without another login.

A typical review covers SSO configuration, who administers the workspace, and which groups each collection is scoped to. Most customers complete it inside the pilot rather than before it.

What about Ida, the AI assistant?

Ida is a panel inside Hives.co, not a separate tool. It reads across your collections to summarise submissions, flag duplicates and surface themes, and it suggests rather than decides: you still make the calls.

Before you assume anything about where AI processing happens, ask us. We tell you which sub-processors Ida uses and how the data flows, in writing, and if your policy needs Ida switched off for a collection or a workspace, that is a setting rather than a negotiation.

Certifications and documents

We would rather tell you exactly where we stand than put a badge on this page. Ask for any of the following and you get the current version in writing:

  • Data processing agreement (DPA)
  • Sub-processor list with hosting regions
  • Security overview for your IT review
  • Our current certification and audit status, stated plainly
  • The Enterprise plan's SLA and custom security and compliance terms

Security questionnaire? The founders answer it themselves. Their addresses are on the about page.

Questions legal and IT usually ask

Where is our data stored?

In the EU, by default. Hives.co is a Swedish company and customer data stays in Europe. The provider, region and sub-processor list are available in writing on request.

Do you support single sign-on?

Yes, for Microsoft and Google, on every plan including Core. People without SSO sign in with a one-time passcode instead of a stored password.

Do all employees need an account?

No. Frontline colleagues can contribute through a QR code or a link without a company account. SSO is there for the people who have one.

Can we get a data processing agreement?

A DPA is part of the contract. Ask and we send the current version before the pilot starts, together with the sub-processor list.

Can employees submit ideas anonymously?

Yes. Anonymous contribution is a setting per collection, so a sensitive topic can be anonymous while a named campaign runs alongside it.

Are you ISO 27001 or SOC 2 certified?

Ask us and we tell you our current status in writing rather than hinting at it here. Enterprise customers can also add their own security and compliance requirements to the contract.

Who answers our security questionnaire?

The founders. Send it with your demo request or to the addresses on the about page, and bring someone from IT to the call so the SSO and hosting questions are settled on the spot.

Bring IT to the first call.

Twenty minutes is usually enough to settle hosting, SSO and the DPA. The Enterprise plan adds SLAs and custom security and compliance terms if you need them.

Used by Progress Makers at