26Eight HUB
Security and Compliance

Controlled access for shared operating infrastructure.

26Eight uses an invitation-first access model for protected HUB resources. Access is granted to a named person or organization, for an explicit purpose and resource scope, for a defined period, with approval and revocation responsibility.

Control status: This statement describes the governing standard and current operating direction. It is not a legal certification, manufacturer authorization, or guarantee of regulatory compliance.

Hat Status classifications

White Hat - Authorized External. Approved dealers and commercial partners may access only their assigned HUB, Brand Spaces, applications, approved product resources, buy-in workflows, and commercial materials explicitly included in their grant.

Red Hat - Temporary Restricted. Prospects, evaluators, event participants, and exception-based collaborators receive narrow, time-limited access to a named project or resource.

Black Hat - Internal Operator. Authorized 26Eight operators and representatives may use internal approval, routing, curation, audit, and revocation tools according to their internal role.

Operating controls

Management responsibility

26Eight management is responsible for approving the control owner, maintaining the access-grant registry, reviewing active grants, investigating suspected misuse, rotating secrets, preserving audit records, and ensuring that manufacturer agreements and applicable privacy, tax, confidentiality, and commercial requirements are not overridden by HUB access.

Recipient responsibility

Recipients must use truthful identity and business information, protect confidential materials, avoid redistribution, submit accurate applications and tax documents, and report loss, compromise, or misdirected access immediately.

Limitations and escalation

Hat Status does not itself create dealer authorization, credit approval, tax exemption, pricing entitlement, agency authority, or manufacturer approval. Questions involving personal data, regulated information, contractual restrictions, or suspected unauthorized access must be escalated to 26Eight management and appropriate professional counsel.