Skip to main content

Security & Incident Response

Effective: August 17, 2026 · Last updated: August 19, 2026

How Outrevio prepares to respond

Outrevio maintains bounded security, audit, diagnostic, correlation, rate-limit, and authorization events so suspected abuse or failures can be investigated without intentionally copying full CRM notes or request bodies into the persistent event store. Privileged observability tools are used to inspect retained signals and request traces.

A warning, failed login, blocked request, provider outage, or alert threshold does not by itself mean that personal information was exposed. Incident response begins with fact-finding and containment rather than an automatic breach declaration.

Incident-response stages

  1. Confirm and triage the signal without assuming that an alert is a confirmed breach.
  2. Contain active risk while preserving relevant evidence.
  3. Identify affected systems, accounts, data categories, integrations, time range, and jurisdictions.
  4. Revoke or rotate affected sessions, OAuth/MCP grants, provider credentials, and other secrets where appropriate.
  5. Preserve bounded logs, correlation IDs, timestamps, and configuration evidence without unnecessarily copying CRM content.
  6. Escalate to the designated security owner and obtain legal review of notification duties.
  7. Notify affected people or authorities when the reviewed facts and applicable requirements call for notice.
  8. Recover safely, monitor for recurrence, document corrective actions, and complete a post-incident review.

Legal notification decisions are not automated

Outrevio does not use an automated rule to decide that a legally reportable breach occurred or to decide whether a particular person, state regulator, federal regulator, law-enforcement body, insurer, customer, or other party must receive notice. Those duties can depend on the affected data, residency, contract, industry, encryption or access facts, timing, and then-current law.

When an incident may involve unauthorized access to personal information, the facts must be escalated for human security and legal review. Required notices, if any, should be made within the applicable legal or contractual timeframes after that review—not delayed for product convenience and not sent automatically from an unverified alert.

Credential and integration containment

Depending on the incident, containment may include invalidating first-party sessions and refresh tokens; revoking MCP/OAuth grants; disconnecting or rotating Google, Meta/WhatsApp, AI-provider, infrastructure, or other credentials; disabling affected functionality; and restricting account access. Outrevio's existing ownership and revocation boundaries remain part of the incident-response design.

Evidence and privacy during an investigation

Investigation data should be limited to what is reasonably necessary to understand and respond to the incident. Outrevio's persistent application event store is intentionally designed around bounded metadata and retention classes. An incident does not create permission to broadly copy unrelated contact notes, imported files, AI content, or other CRM information into logs.

Report a security issue

Security reports can be sent to support@outrevio.com. Please do not include passwords, access tokens, private keys, or unnecessary CRM contents in the initial report.

Related policies

Review the Privacy Policy, Data Deletion Instructions, and AI & External Connections disclosure for related data, retention, revocation, and external-connection controls.