Security · Incident response
Report a security incident.
Tell us what happened. We log it immediately and the response team works the case through containment, evidence preservation, notification, corrective action, and closure. You can follow your reference id at any time.
How we respond
Every incident moves through the same five phases — containment first, evidence next, communications alongside, corrective plans during remediation, and closure with a verified record.
- Containment. First responders isolate the affected systems, revoke access, and stop further damage. Each action is logged.
- Evidence preservation. Logs, screenshots, and artifacts are sealed with sha256 fingerprints and chain-of-custody notes.
- Notification assessment. Severity drives a deadline; the team records which audiences (internal, regulator, customer, partner, media) need to be notified and dispatches the communications.
- Corrective action. Each remediation step is captured as an action — owner, due date, status — and verified before closure.
- Closure. The incident is closed only when every corrective action is verified or explicitly marked as won't fix. The full audit trail stays available afterwards.