Security

Incident Response Policy

How OctaVertex Media detects, contains, and communicates security or personal data incidents for Vertex CRM.

Reviewed August 2026

1. Purpose

Define how OctaVertex Media detects, responds to, and communicates security or personal data incidents affecting Vertex CRM.

2. What is an incident

Unauthorized access, data breach, ransomware, prolonged availability loss affecting confidentiality/integrity, or confirmed abuse of Meta webhooks/tokens that exposes customer data.

3. Reporting

Internal team members escalate immediately to on-call/ops. Customers and researchers report via Contact with subject “Security” or “Incident”. Do not include passwords or full dumps in the first email.

4. Response steps

  1. Contain — revoke tokens, disable compromised accounts, block abusive traffic
  2. Investigate — preserve logs, determine scope and affected tenants
  3. Eradicate & recover — patch, rotate secrets, restore from clean backups if needed
  4. Notify — inform affected Controllers without undue delay when personal data is breached, with known facts and mitigation steps
  5. Post-incident review — document root cause and preventive actions

5. Customer responsibilities

Report suspected account compromise promptly; reset passwords; review user list and Meta connections after notification.

6. Related

Security hub · Vulnerability management · Backups

Last updated: August 2026.