1. Account protection
Hookioz supports password-based authentication, email verification, password reset workflows, login notifications, and optional time-based one-time password two-factor authentication with recovery codes. Customers are responsible for maintaining credential confidentiality and restricting account access to authorized users.
2. Organization isolation
Product data is scoped by organization context so that sources, events, members, and billing settings remain logically separated between workspaces. Authorization decisions are evaluated against the current organization context and the role assigned to the authenticated user.
3. Secret and credential handling
Credentials are stored in protected form and operational access is limited according to the needs of the service. Customers are responsible for protecting and rotating downstream secrets, webhook credentials, and destination-side authentication values configured in their own integrations.
4. Operational safeguards
Hookioz applies rate limits, status tracking, retries, dead-letter handling, and retention workflows to keep webhook traffic observable and controlled. Historical payload content may be redacted according to the retention behavior associated with the active plan and product configuration.
5. Monitoring and incident response
We monitor platform behavior and investigate suspicious or degraded service conditions using operational alerts, diagnostics, and support workflows. If a material security issue is determined to affect customers, we may communicate through the most appropriate available channel, including email, account notices, or other operational communication methods.
6. Shared responsibility
Customers remain responsible for endpoint security, organization membership hygiene, credential rotation, webhook payload content, and prompt review of account alerts. Effective security depends both on the hosted platform and on the systems, users, and procedures that connect to it.