Legal
Security Overview
Last updated: July 19, 2026
Our Commitment
Mavrix Digital is built for operators who entrust us with business-critical data across multiple companies. Security is not an afterthought — it is foundational to how we design, build, and operate the Platform. This page outlines the technical and organisational controls we maintain.
Infrastructure
- All data is stored on infrastructure hosted in SOC 2-certified data centres.
- Traffic between your browser and our servers is encrypted using TLS 1.2 or higher.
- Data at rest is encrypted using AES-256.
- Production databases are isolated from internet-accessible networks and accessed only via encrypted private channels.
- Automated daily backups with point-in-time recovery capability.
Authentication and Access Control
- Passwords are hashed using bcrypt with appropriate cost factors; we never store plaintext credentials.
- Multi-factor authentication (MFA) is available and encouraged for all operator accounts.
- Role-based access controls ensure team members access only the data their role requires.
- Internal access to production systems by Mavrix Digital staff follows least-privilege principles and is logged.
- API tokens are scoped, short-lived where possible, and encrypted at rest.
Application Security
- We conduct regular dependency audits and apply security patches promptly.
- Input validation and output encoding are applied throughout the application to prevent injection attacks.
- CSRF protections and secure cookie flags are enforced on all authenticated endpoints.
- Rate limiting is applied to authentication and API endpoints to mitigate brute-force and denial-of-service attempts.
- Webhook payloads from third-party services are validated using signature verification and timestamp checks to prevent replay attacks.
Monitoring and Incident Response
- Application and infrastructure logs are retained for security analysis and anomaly detection.
- Automated alerting is in place for unusual access patterns or errors.
- In the event of a confirmed data breach affecting your account, we will notify you within 72 hours of becoming aware, consistent with PIPEDA and GDPR breach notification requirements.
Third-Party Sub-processors
We work with a small number of vetted sub-processors (cloud hosting, payment processing, email delivery) that are bound by data processing agreements. A full list of sub-processors is available on request.
Reporting a Vulnerability
If you discover a security vulnerability in the Mavrix Digital Platform, please report it responsibly to: security@mavrixdigital.ca
Please include a description of the vulnerability, steps to reproduce, and any relevant screenshots or proof-of-concept code. We will acknowledge your report within 2 business days and keep you informed as we investigate and remediate. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.
Questions
For general security questions, contact us at security@mavrixdigital.ca. For privacy-related inquiries, see our Privacy Policy.