Breach notification

If something happens, you hear from us first

Regulators set the floor (72 hours under GDPR, similar under DORA). We commit to faster, with explicit time bounds by severity, named channels, and a written post-incident review that the customer’s auditor can rely on.

First notice (SEV-1)

≤ 1 hour

From confirmed event to outbound

Written PIR

≤ 72 hours

Auditor-grade timeline by day 14

Channel

Multi-path

Page · email · /status · /transparency

Standing test

Quarterly

Drilled on /tabletops with customers

Time bounds by severity

SeverityCriteriaFirst notice
SEV-1Confirmed unauthorised access to customer data, or material money movement risk.≤ 1 hour
SEV-2Significant degradation, integrity drift, or near-miss of SEV-1.≤ 4 hours
SEV-3Localised issue or supplier-side event with limited impact.≤ 24 hours
SEV-4Informational; no customer action required.Weekly digest

What every notice contains

  • What we know, what we don’t, and the next time we will update you.
  • Affected tenants, data categories, and approximate counts (or “under investigation”, never silent).
  • Customer actions required, in plural-imperative, with no marketing language.
  • Named DRI on our side reachable on the bridge for the duration.

Governing rules

  • GDPR Art. 33/34 — controller notification within 72 hours; we beat it.
  • DORA — major ICT-related incident reporting templates supported out of the box.
  • SOC 2 CC7.3 — security incident communications evidenced from this page.
  • Contractual — these commitments are bound into the MSA and underwritten by /sla-credits.