Skip to content
DocumentationSecurityIncident response
SecurityCurrent contractVersion DOCS-2.0

Incident response

A preservation-first workflow to detect, classify, contain, recover, communicate and learn from incidents.

How to interpret this document

This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.

Detect

Use alerts, observability, user reports and audit evidence to identify abnormal behavior and determine which systems may be involved.

Classify

Assess impact on authentication, confidentiality, integrity, availability, billing, integrations and measurement reliability.

Contain

Prefer disabling the affected workflow, integration or rollout state rather than deleting historical evidence. Launch Control can move the product back to hold.

Preserve evidence

AUD-2.0, identity events, billing reconciliation, telemetry and related records should be preserved. Legal hold can be applied when appropriate.

Recover

Restore a known-good checkpoint, correct data through auditable and idempotent operations and rerun readiness checks.

Communicate

Notification duties and timelines for customers, regulators and data subjects depend on law, contract and approved legal policy.

Learn

Record root cause, contributing factors, gaps, corrective actions, owner and a verification plan for the fix.