Legal

Security Overview

Last updated: July 19, 2026

Our Commitment

Mavrix Digital is built for operators who entrust us with business-critical data across multiple companies. Security is not an afterthought — it is foundational to how we design, build, and operate the Platform. This page outlines the technical and organisational controls we maintain.

Infrastructure

  • All data is stored on infrastructure hosted in SOC 2-certified data centres.
  • Traffic between your browser and our servers is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256.
  • Production databases are isolated from internet-accessible networks and accessed only via encrypted private channels.
  • Automated daily backups with point-in-time recovery capability.

Authentication and Access Control

  • Passwords are hashed using bcrypt with appropriate cost factors; we never store plaintext credentials.
  • Multi-factor authentication (MFA) is available and encouraged for all operator accounts.
  • Role-based access controls ensure team members access only the data their role requires.
  • Internal access to production systems by Mavrix Digital staff follows least-privilege principles and is logged.
  • API tokens are scoped, short-lived where possible, and encrypted at rest.

Application Security

  • We conduct regular dependency audits and apply security patches promptly.
  • Input validation and output encoding are applied throughout the application to prevent injection attacks.
  • CSRF protections and secure cookie flags are enforced on all authenticated endpoints.
  • Rate limiting is applied to authentication and API endpoints to mitigate brute-force and denial-of-service attempts.
  • Webhook payloads from third-party services are validated using signature verification and timestamp checks to prevent replay attacks.

Monitoring and Incident Response

  • Application and infrastructure logs are retained for security analysis and anomaly detection.
  • Automated alerting is in place for unusual access patterns or errors.
  • In the event of a confirmed data breach affecting your account, we will notify you within 72 hours of becoming aware, consistent with PIPEDA and GDPR breach notification requirements.

Third-Party Sub-processors

We work with a small number of vetted sub-processors (cloud hosting, payment processing, email delivery) that are bound by data processing agreements. A full list of sub-processors is available on request.

Reporting a Vulnerability

If you discover a security vulnerability in the Mavrix Digital Platform, please report it responsibly to: security@mavrixdigital.ca

Please include a description of the vulnerability, steps to reproduce, and any relevant screenshots or proof-of-concept code. We will acknowledge your report within 2 business days and keep you informed as we investigate and remediate. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.

Questions

For general security questions, contact us at security@mavrixdigital.ca. For privacy-related inquiries, see our Privacy Policy.