Security · Incident response

Report a security incident.

Tell us what happened. We log it immediately and the response team works the case through containment, evidence preservation, notification, corrective action, and closure. You can follow your reference id at any time.

One sentence summarising what's happening.

Category
Severity

At least 20 characters. The full text is preserved in the audit log.

We will only use this to follow up with you about this incident.

Submitting creates an incident row + an audit event. The response team is paged per severity; you'll see the reference id once we receive it.

How we respond

Every incident moves through the same five phases — containment first, evidence next, communications alongside, corrective plans during remediation, and closure with a verified record.

  1. Containment. First responders isolate the affected systems, revoke access, and stop further damage. Each action is logged.
  2. Evidence preservation. Logs, screenshots, and artifacts are sealed with sha256 fingerprints and chain-of-custody notes.
  3. Notification assessment. Severity drives a deadline; the team records which audiences (internal, regulator, customer, partner, media) need to be notified and dispatches the communications.
  4. Corrective action. Each remediation step is captured as an action — owner, due date, status — and verified before closure.
  5. Closure. The incident is closed only when every corrective action is verified or explicitly marked as won't fix. The full audit trail stays available afterwards.