Security incident response policy
Effective June 21, 2026
This policy describes how Informly Inc. ("Informly") detects, classifies, responds to, and learns from security incidents affecting the confidentiality, integrity, or availability of personal data — including data we process on behalf of our customers and the end-customers they serve. It applies to all Informly personnel and to every system that stores or processes that data.
1. What counts as a security incident
A security incident is any confirmed or reasonably suspected event that compromises, or threatens to compromise, the security of personal data or the systems that hold it — for example unauthorized access, data exfiltration, account compromise, malware, a vulnerability under active exploitation, or accidental disclosure or loss of data.
2. Severity levels
SEV-1 (Critical). Confirmed or likely unauthorized access to, loss of, or disclosure of personal data; or a full outage of a system holding personal data. Immediate response.
SEV-2 (High). A material security weakness with credible exposure but no confirmed data access — e.g. a critical vulnerability, a contained intrusion, or repeated failed-access anomalies. Response within hours.
SEV-3 (Low / Moderate). Limited-impact issues with no exposure of personal data — e.g. a non-exploited vulnerability or a single misconfiguration. Handled in the normal engineering cycle.
3. Roles + responsibilities
Incident Lead. The engineer who declares an incident owns it until handed off. They coordinate the response, keep the timeline, and decide on escalation and communication.
Engineering responders. Investigate, contain, and remediate under the Incident Lead's direction.
Founder / accountable owner. Approves customer and regulator notifications and any public disclosure; engages legal counsel where required.
4. Response lifecycle
Detect. Incidents are surfaced through monitoring and alerting, provider notifications, and our responsible-disclosure channel (security@informly.co).
Triage. The Incident Lead assigns a severity, opens a tracked incident record, and starts a timeline.
Contain. Stop the spread — revoke credentials and sessions, isolate affected systems, block malicious access.
Eradicate + recover. Remove the root cause, restore from known-good backups where needed, and verify integrity before returning systems to service.
Review. Every SEV-1 and SEV-2 gets a written post-incident review with root cause and follow-up actions.
5. Evidence handling
We preserve relevant logs, access records, and system state for affected systems for the duration of the investigation and the post-incident review, so that root cause can be established and, where required, provided to customers, auditors, or regulators.
6. Notification
Customers.Where a personal data breach affects a customer's data, we notify the affected customer without undue delay and in any case within 72 hours of becoming aware, with the information they need to meet their own obligations (see our DPA, §8).
Platforms + regulators. Where an incident involves data received through a connected platform (e.g. Shopify), we notify that platform as required by our agreement with them. We support customers in meeting any regulatory notification deadlines that apply to them.
7. Contact
Report a suspected incident or vulnerability to security@informly.co. We acknowledge within 24 hours and triage within 72 hours.