Enterprise data is sensitive. And we left nothing to chance to keep it secure. We combine enterprise-grade security features with regular audits and updates to our applications, systems, and networks to ensure customer data is protected.
EvonSys will maintain commercially reasonable administrative, physical and technical safeguards for the Platform to protect against the accidental or unauthorized access, use, alteration or disclosure of Customer Content properly uploaded to, or ingested by, the Platform and processed or stored on a computer and/or computer network owned or controlled by EvonSys in connection with the Platform. If, at any time, EvonSys fails to comply with this Section, Customer may promptly notify EvonSys in writing of any such noncompliance. EvonSys will, within thirty (30) days of receipt of such written notification, either correct the noncompliance or provide Customer with a plan for correcting the noncompliance. If the noncompliance is not corrected or if a reasonably acceptable plan for correcting the noncompliance is not established during such period, Customer may terminate this Agreement as its sole and exclusive remedy for such noncompliance.
To the extent required pursuant to applicable laws, the Parties will enter a Data Processing Addendum in a form provided by EvonSys.
For each individual Authorized User, the Platform stores encrypted OAuth Tokens that enable publishing content on the Authorized User’s behalf. OAuth Tokens are accessible only within the authenticated session of the corresponding Authorized User and are limited solely to the Customer’s tenant of the Platform. All OAuth Tokens are encrypted at rest using the Fernet scheme from the widely adopted Python cryptography library. Fernet provides symmetric authenticated encryption, meaning the token is both encrypted and integrity protected before it is written to the database. EvonSys personnel never have visibility into the plaintext tokens, and the encrypted tokens are used exclusively to deliver the Platform. OAuth Tokens are retained only for the period necessary to operate the Platform and are deleted in accordance with the data retention policy when no longer needed. For Customer pages or corporate accounts, OAuth Tokens may be stored at the Customer level and are administered by the Administrator, including with respect to deletions or revocations.
We share Stories around Employee -led Distribution + Growth every 2 weeks. No Spam