Third Party Index

Snapshot 44972

Document
Security page
URL
https://www.morphed.io/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
39678 bytes
SHA-256 (raw)
94f1edfcac5834c1464699e80968dda710ba20056d6442de07ac7e60155dbc36
SHA-256 (normalized text)
42b65c366492dc289ae060487842e83f7ee3ff7da72daf403df8cc895c953af0

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security & compliance
Security & Infrastructure
Last updated: July 2026
EU-Based Infrastructure
Personal data is stored and processed in EU infrastructure (Frankfurt).
Anonymized summaries may be sent to AI providers for analysis.
Morphed stores synced HubSpot data (encrypted) to deliver the service.
Database
Supabase EU Central
Frankfurt, Germany
Application Servers
Render EU Region
Frankfurt, Germany
Static Assets
Vercel EU Region
Frankfurt, Germany
Personal data is stored and processed in EU infrastructure (Frankfurt).
Data Encryption
Encryption at Rest
AES-256 encryption for all database storage
Encrypted backups with separate encryption keys
Key rotation and management via secure key vaults
Encrypted file storage for uploaded content
Encryption in Transit
TLS 1.3 for all API communications
Perfect Forward Secrecy (PFS) enabled
Certificate pinning for critical connections
Encrypted OAuth token exchange with HubSpot
Database Connection Security
SSL/TLS required for all database connections
Connection pooling with encrypted credentials
Single connection per tenant for EU Central pooler compatibility
Automatic connection termination and reconnection handling
Access Control & Authentication
HubSpot OAuth Connection
HubSpot access uses Morphed’s OAuth connection
Authorized reads run immediately. Every write waits for one exact, one-time approval bound to the operator and staged action.
Secure token storage with AES-256-GCM encryption
Tokens are encrypted and stored separately
Tokens are scoped to requested permissions
MCP (AI Interactions)
ChatGPT and Claude use Morphed MCP
Morphed MCP traffic is encrypted in transit, authenticated, and scoped to the actor and portal
WhatsApp, Slack, email, and Telegram use Morphed’s direct backend instead of MCP
HubSpot access uses OAuth instead of MCP
ChatGPT and Claude use Morphed MCP. HubSpot uses OAuth. Both paths are encrypted in transit and scoped.
Role-Based Access Control (RBAC)
Separate roles for workspace owners, customers, and admins
Portal-level access isolation (users see only their assigned portals)
Session-based authentication with secure httpOnly cookies
Multi-factor authentication support
Multi-Tenant Isolation
Dedicated data pipelines per workspace
Query-level tenant filtering to prevent cross-tenant access
Separate AI processing contexts per workspace
Zero cross-contamination between workspaces
AI Processing Security
Anonymized Summaries Only
We do not intentionally send personal data to AI providers. Only anonymized/aggregated summaries may be transmitted for analysis.
Step 1: HubSpot data syncs to EU servers (encrypted)
Step 2: PII automatically redacted (names, emails, phone numbers, addresses)
Step 3: Financial data anonymized (deal amounts, revenue figures)
Step 4: Data aggregated into non-personal summaries
Step 5: Only anonymized summaries sent through encrypted provider connections
Step 6: AI processes trends and insights without personal details
Model Context Protocol (MCP) Security
TLS encryption in transit for MCP communications
OAuth or scoped API key authentication according to the connection
Rate limiting and request validation
Actor, portal, tool call, and write approval decisions recorded in audit history
We do not intentionally send personal data to AI providers, and we configure providers to minimize retention where available
AI Redaction & Anonymization Controls
PII detection and redaction runs before any AI request
Small cohort suppression (no outputs for <10 records)
Free-text fields are locally summarized then re-redacted before sending
Planned: Automated regression tests to validate redaction coverage
Application Security
Input Validation & Sanitization
SQL injection prevention
XSS protection
CSRF token validation
Request size limits (2MB)
Rate Limiting
100 requests/minute (global)
50 requests/minute (per portal)
IP-based throttling
DDoS protection
Security Headers
Helmet.js security middleware
Content Security Policy (CSP)
HSTS enabled
X-Frame-Options protection
CORS Protection
Explicit origin allowlist
Credential enforcement
Pre-flight request validation
Domain-based access control
Monitoring & Incident Response
24/7 Security Monitoring
Real-time error tracking and alerting
Automated security event logging
Database pool health monitoring
API endpoint performance tracking
Suspicious activity detection
Incident Response
Documented incident response procedures
Breach notification within 72 hours (GDPR compliance)
Root cause analysis for all incidents
Post-incident reporting and improvements
Audit Logging
All API requests logged with request IDs
Authentication and authorization events tracked
Data access patterns monitored
Logs retained for 90 days
Compliance & Certifications
GDPR Compliant
Full compliance with EU General Data Protection Regulation
SOC 2 Controls-Aligned
SOC 2 controls-aligned (Type II roadmap)
HubSpot Program Alignment
Adheres to HubSpot security and data handling requirements
ISO 27001 Best Practices
Aligned to ISO 27001 best practices
Backup & Disaster Recovery
Automated Backups
Daily automated database backups
Encrypted backup storage (separate encryption keys)
Encrypted backups are retained for 30 days and are then purged
Point-in-time recovery capability
Disaster Recovery
Multi-region backup replication within EU
Target RTO: < 4 hours (tested quarterly)
Target RPO: < 1 hour (tested quarterly)
Regular disaster recovery testing
Vulnerability Management
Regular dependency updates and security patches
Automated vulnerability scanning (npm audit, Snyk)
Quarterly penetration testing
Bug bounty program (coming soon)
Responsible disclosure policy
Contact Our Security Team
For security inquiries, vulnerability reports, or security documentation:
Email: [email protected]
Data Protection Officer: [email protected]
We respond to security inquiries within 24 hours.