Skip to content

Security & Compliance

How Oclavex protects credentials and secrets, handles privacy requests, stores your data, and versions its API.

  • Credentials & secrets — how API client secrets, webhook signing secrets, license tokens and the signing key are issued, rotated and revoked.
  • Privacy & data-subject requests — the admin-filed DSR flow, the User.Erased signal, and what erasure retains in de-identified form.
  • Legal & data residency — the controller–processor relationship, where your data lives, and the data processing agreement (DPA).
  • API versioning — one v1 surface, additive evolution, and what would count as breaking.