Breach notification
If something happens, you hear from us first
Regulators set the floor (72 hours under GDPR, similar under DORA). We commit to faster, with explicit time bounds by severity, named channels, and a written post-incident review that the customer’s auditor can rely on.
First notice (SEV-1)
≤ 1 hour
From confirmed event to outbound
Written PIR
≤ 72 hours
Auditor-grade timeline by day 14
Channel
Multi-path
Page · email · /status · /transparency
Standing test
Quarterly
Drilled on /tabletops with customers
Time bounds by severity
| Severity | Criteria | First notice |
|---|---|---|
| SEV-1 | Confirmed unauthorised access to customer data, or material money movement risk. | ≤ 1 hour |
| SEV-2 | Significant degradation, integrity drift, or near-miss of SEV-1. | ≤ 4 hours |
| SEV-3 | Localised issue or supplier-side event with limited impact. | ≤ 24 hours |
| SEV-4 | Informational; no customer action required. | Weekly digest |
What every notice contains
- What we know, what we don’t, and the next time we will update you.
- Affected tenants, data categories, and approximate counts (or “under investigation”, never silent).
- Customer actions required, in plural-imperative, with no marketing language.
- Named DRI on our side reachable on the bridge for the duration.
Governing rules
- GDPR Art. 33/34 — controller notification within 72 hours; we beat it.
- DORA — major ICT-related incident reporting templates supported out of the box.
- SOC 2 CC7.3 — security incident communications evidenced from this page.
- Contractual — these commitments are bound into the MSA and underwritten by /sla-credits.