This Incident Response Policy (“Policy”) sets out the process Fyltre Ltd (“Fyltre,” “we,” “our,” or “us”) follows to respond to security incidents affecting customer data or the systems that process it. It applies to all employees, contractors, and systems involved in the operation of the Fyltre service.
What counts as an incident
A security incident is any event that compromises, or has the potential to compromise, the confidentiality, integrity, or availability of customer data or Fyltre systems. Examples include:
- Unauthorised access to accounts, credentials, or production systems
- Exposure or loss of customer data
- Malware, ransomware, or compromise of a dependency or subprocessor
- Denial-of-service or abuse that degrades availability
- Loss or theft of a device with access to production systems
Detection & reporting
- Incidents may be detected through monitoring, audit logs, rate-limit alerts, subprocessor notifications, or reports from users and security researchers.
- Anyone — staff or external — can report a suspected incident via our contact channel. Reports are triaged promptly.
- External vulnerability reports are handled under our Vulnerability Disclosure Policy.
Severity classification
- Critical — confirmed exposure of customer data or full system compromise. Immediate response.
- High — significant risk to data or availability, no confirmed exposure yet. Response within hours.
- Medium / Low — limited or contained impact. Response within standard working timelines.
Response process
- 1. Identify — confirm the incident, assign a severity, and designate a response owner.
- 2. Contain — limit impact by revoking compromised credentials, isolating affected systems, or disabling affected functionality.
- 3. Eradicate — remove the root cause (patch, rotate keys, remove malicious access).
- 4. Recover — restore service from known-good state and verify integrity before returning to normal operation.
- 5. Review — conduct a post-incident review to capture lessons learned and prevent recurrence.
Notification
- Where a personal data breach is likely to result in a risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR / UK GDPR.
- Affected users will be notified without undue delay where the breach is likely to result in a high risk to their rights, with clear information on what happened and what to do.
- Where an incident involves Google user data, we will notify Google in line with the Google API Services User Data Policy.
Evidence & record-keeping
All incidents are documented — including timeline, impact, actions taken, and notifications made. Audit logs and supporting evidence are preserved to support investigation and any required regulatory reporting.
Review
This Policy is reviewed at least annually and updated after any significant incident or material change to our systems.
Contact
To report an incident or ask about this Policy:
Fyltre Ltd — get in touch