Security

Vulnerability Management Policy

How Vertex CRM identifies, prioritizes, and remediates security vulnerabilities.

Reviewed August 2026

1. Purpose

How Vertex CRM identifies, prioritizes, and remediates security vulnerabilities.

2. Sources

  • Dependency updates and advisories for Go modules and system packages
  • Code review and secure development practices
  • External reports via Contact (subject “Security”)
  • Monitoring of abnormal auth, webhook, and rate-limit events

3. Prioritization

Critical/high issues affecting authentication, tenancy isolation, secret exposure, or remote code execution are remediated first. Medium/low issues are scheduled with regular releases.

4. Remediation & disclosure

Patches are deployed through the normal release pipeline. We ask researchers not to publicly disclose issues until a fix is available. Customer notification follows the Incident Response Policy when exploitation or data impact is confirmed.

5. Related

Secure development · Security hub

Last updated: August 2026.