1. Overview
This Information Security page summarizes how OctaVertex Media protects Vertex CRM. It is a public summary for customers and Meta App Review—not a substitute for a signed security questionnaire or private penetration-test report.
2. Security policy index
- Access Control Policy
- Data Encryption Policy
- Incident Response Policy
- Backup Policy
- Vulnerability Management Policy
- Secure Development Policy
- Data Retention Policy
- Data Deletion Policy
3. Core controls
- Authentication with hashed passwords; optional MFA for users
- Session cookies and role-based access control (RBAC) within each organization
- Tenant-scoped data access in application queries
- TLS in transit (terminated at reverse proxy / load balancer in production)
- Encryption of Meta/integration tokens at rest when
SECRET_KEYis configured - Webhook signature verification for Meta/WhatsApp where implemented
- Audit logging for sensitive administrative actions
- Rate limiting on public contact forms
4. Shared responsibility
Customers configure users, roles, integrations, and what personal data they store. OctaVertex Media secures the platform and infrastructure under its control. Customers should use strong passwords, enable MFA, and grant least privilege.
5. Contact
Security reports: Contact (subject “Security”). See also Compliance hub.
Last updated: August 2026.