1. Purpose
How Vertex CRM identifies, prioritizes, and remediates security vulnerabilities.
2. Sources
- Dependency updates and advisories for Go modules and system packages
- Code review and secure development practices
- External reports via Contact (subject “Security”)
- Monitoring of abnormal auth, webhook, and rate-limit events
3. Prioritization
Critical/high issues affecting authentication, tenancy isolation, secret exposure, or remote code execution are remediated first. Medium/low issues are scheduled with regular releases.
4. Remediation & disclosure
Patches are deployed through the normal release pipeline. We ask researchers not to publicly disclose issues until a fix is available. Customer notification follows the Incident Response Policy when exploitation or data impact is confirmed.
5. Related
Secure development · Security hub
Last updated: August 2026.