Snapshot 44972
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security & compliance Security & Infrastructure Last updated: July 2026 EU-Based Infrastructure Personal data is stored and processed in EU infrastructure (Frankfurt). Anonymized summaries may be sent to AI providers for analysis. Morphed stores synced HubSpot data (encrypted) to deliver the service. Database Supabase EU Central Frankfurt, Germany Application Servers Render EU Region Frankfurt, Germany Static Assets Vercel EU Region Frankfurt, Germany Personal data is stored and processed in EU infrastructure (Frankfurt). Data Encryption Encryption at Rest AES-256 encryption for all database storage Encrypted backups with separate encryption keys Key rotation and management via secure key vaults Encrypted file storage for uploaded content Encryption in Transit TLS 1.3 for all API communications Perfect Forward Secrecy (PFS) enabled Certificate pinning for critical connections Encrypted OAuth token exchange with HubSpot Database Connection Security SSL/TLS required for all database connections Connection pooling with encrypted credentials Single connection per tenant for EU Central pooler compatibility Automatic connection termination and reconnection handling Access Control & Authentication HubSpot OAuth Connection HubSpot access uses Morphed’s OAuth connection Authorized reads run immediately. Every write waits for one exact, one-time approval bound to the operator and staged action. Secure token storage with AES-256-GCM encryption Tokens are encrypted and stored separately Tokens are scoped to requested permissions MCP (AI Interactions) ChatGPT and Claude use Morphed MCP Morphed MCP traffic is encrypted in transit, authenticated, and scoped to the actor and portal WhatsApp, Slack, email, and Telegram use Morphed’s direct backend instead of MCP HubSpot access uses OAuth instead of MCP ChatGPT and Claude use Morphed MCP. HubSpot uses OAuth. Both paths are encrypted in transit and scoped. Role-Based Access Control (RBAC) Separate roles for workspace owners, customers, and admins Portal-level access isolation (users see only their assigned portals) Session-based authentication with secure httpOnly cookies Multi-factor authentication support Multi-Tenant Isolation Dedicated data pipelines per workspace Query-level tenant filtering to prevent cross-tenant access Separate AI processing contexts per workspace Zero cross-contamination between workspaces AI Processing Security Anonymized Summaries Only We do not intentionally send personal data to AI providers. Only anonymized/aggregated summaries may be transmitted for analysis. Step 1: HubSpot data syncs to EU servers (encrypted) Step 2: PII automatically redacted (names, emails, phone numbers, addresses) Step 3: Financial data anonymized (deal amounts, revenue figures) Step 4: Data aggregated into non-personal summaries Step 5: Only anonymized summaries sent through encrypted provider connections Step 6: AI processes trends and insights without personal details Model Context Protocol (MCP) Security TLS encryption in transit for MCP communications OAuth or scoped API key authentication according to the connection Rate limiting and request validation Actor, portal, tool call, and write approval decisions recorded in audit history We do not intentionally send personal data to AI providers, and we configure providers to minimize retention where available AI Redaction & Anonymization Controls PII detection and redaction runs before any AI request Small cohort suppression (no outputs for <10 records) Free-text fields are locally summarized then re-redacted before sending Planned: Automated regression tests to validate redaction coverage Application Security Input Validation & Sanitization SQL injection prevention XSS protection CSRF token validation Request size limits (2MB) Rate Limiting 100 requests/minute (global) 50 requests/minute (per portal) IP-based throttling DDoS protection Security Headers Helmet.js security middleware Content Security Policy (CSP) HSTS enabled X-Frame-Options protection CORS Protection Explicit origin allowlist Credential enforcement Pre-flight request validation Domain-based access control Monitoring & Incident Response 24/7 Security Monitoring Real-time error tracking and alerting Automated security event logging Database pool health monitoring API endpoint performance tracking Suspicious activity detection Incident Response Documented incident response procedures Breach notification within 72 hours (GDPR compliance) Root cause analysis for all incidents Post-incident reporting and improvements Audit Logging All API requests logged with request IDs Authentication and authorization events tracked Data access patterns monitored Logs retained for 90 days Compliance & Certifications GDPR Compliant Full compliance with EU General Data Protection Regulation SOC 2 Controls-Aligned SOC 2 controls-aligned (Type II roadmap) HubSpot Program Alignment Adheres to HubSpot security and data handling requirements ISO 27001 Best Practices Aligned to ISO 27001 best practices Backup & Disaster Recovery Automated Backups Daily automated database backups Encrypted backup storage (separate encryption keys) Encrypted backups are retained for 30 days and are then purged Point-in-time recovery capability Disaster Recovery Multi-region backup replication within EU Target RTO: < 4 hours (tested quarterly) Target RPO: < 1 hour (tested quarterly) Regular disaster recovery testing Vulnerability Management Regular dependency updates and security patches Automated vulnerability scanning (npm audit, Snyk) Quarterly penetration testing Bug bounty program (coming soon) Responsible disclosure policy Contact Our Security Team For security inquiries, vulnerability reports, or security documentation: Email: [email protected] Data Protection Officer: [email protected] We respond to security inquiries within 24 hours.