Response phases
1 · Detect
On-call + product signals (auth anomalies, rate-limit spikes, audit spikes). Customer reports via VDP or support.
2 · Contain
Revoke sessions/keys, isolate integrations, freeze risky automations, legal hold when needed.
3 · Eradicate
Root-cause, patch, rotate secrets, verify with regression checks and audit trail.
4 · Recover
Restore service within RTO target. Validate data integrity against RPO. Status page updates.
5 · Notify
Customer notify when legally required or contractually owed. Breach timelines follow GDPR/CCPA where applicable.
6 · Learn
Postmortem, control map updates, evidence vault notes. DR drills scheduled — records are process-only until filed.
Customer communication
Material incidents affecting availability or confidentiality get status updates at /status and, when required, direct notice to workspace admins. We do not publish fake “never breached” claims.