Security Documentation
Documented response procedures for common security and compliance incidents. All playbooks follow a Detect → Contain → Notify → Review cycle. Last reviewed: 2026-04-18.
Triggered by: suspicious login from new device, password reset not initiated by user, or user report.
Detect
Contain
Notify User
Review
Triggered by: vendor security notice, public breach disclosure, or anomalous behavior from a vendor API.
Triggered by: litigation notice, regulatory investigation, or law enforcement request.
| Jurisdiction | Deadline | Authority | Threshold |
|---|---|---|---|
| GDPR (EU/UK) | 72 hours from awareness | Lead DPA in primary EU country | Risk to natural persons |
| CCPA (California) | 30 days to notify consumers | CA AG if 500+ residents affected | Personal info of CA residents |
| HIPAA (US healthcare) | 60 days | HHS + affected individuals | PHI of US patients |
| UAE PDPL | 72 hours to authority, 72h to individuals | UAE DIFC Commissioner / UAE DPA | Serious harm likely |
| Australia Privacy Act | ASAP (no hard deadline) | OAIC | Serious harm likely |
Subject: Important Security Notice — Action Required Dear [Customer Name], We are writing to inform you of a security incident that may have affected your Aegis Firma account. WHAT HAPPENED On [DATE], we identified [BRIEF DESCRIPTION — e.g., "unauthorized access to our database"]. We became aware of this incident on [DETECTION DATE]. WHAT INFORMATION WAS INVOLVED The following types of information may have been affected: [LIST SPECIFIC DATA TYPES]. Your [payment / password data] was NOT affected — [reason, e.g., we do not store card numbers]. WHAT WE ARE DOING • We have [immediate containment actions taken] • We have [remediation steps: rotated keys, patched vulnerability, etc.] • We are working with [Supabase / relevant vendors] to [prevent recurrence] WHAT YOU SHOULD DO 1. [Specific action: reset your password / review your account activity / etc.] 2. Be alert for phishing emails referencing this incident 3. If you notice suspicious activity, contact us via the in-app Feedback page HOW TO CONTACT US If you have questions, sign in to Aegis Firma and use the Feedback page. We sincerely apologize for any concern this may cause. — The Aegis Firma Team
To: [Data Protection Authority / Supervisory Authority name and email] Subject: Personal Data Breach Notification — Aegis Firma / Aegis Digital Systems 1. IDENTITY OF CONTROLLER Name: Aegis Digital Systems Contact: [contact@aegisfirma.com or via in-app support] 2. NATURE OF THE BREACH Type: [Confidentiality / Integrity / Availability breach] Date/time of incident: [DATE TIME UTC] Date/time detected: [DATE TIME UTC] 3. CATEGORIES AND APPROXIMATE NUMBER OF DATA SUBJECTS AFFECTED [e.g., Business email addresses and hashed passwords of approximately X users] 4. LIKELY CONSEQUENCES [e.g., Risk of credential stuffing; no financial data involved] 5. MEASURES TAKEN OR PROPOSED Taken: [List immediate containment steps] Proposed: [List ongoing remediation] 6. CONTACT DETAILS FOR FURTHER INFORMATION Owner contact: [secure channel — owner personal email for regulator use only] We commit to providing updates as the investigation progresses.
Complete within 72 hours of incident closure. Stored in internal incident log.
POST-INCIDENT REVIEW =================== Incident ID: [INC-YYYY-NNN] Severity: [Critical / High / Medium / Low] Date of incident: [DATE] Date closed: [DATE] Reviewed by: [Name] Review date: [DATE — within 72h of closure] 1. EXECUTIVE SUMMARY One paragraph: what happened, impact, resolution. 2. TIMELINE [DATE TIME] — Event 1 (e.g., first indicator of compromise) [DATE TIME] — Event 2 (e.g., confirmed breach) [DATE TIME] — Containment started [DATE TIME] — Service restored / data secured [DATE TIME] — Notifications sent (customers, regulators) [DATE TIME] — Incident closed 3. ROOT CAUSE ANALYSIS (5 WHYs) Why 1: [e.g., Unauthorized access occurred because...] Why 2: [because...] Why 3: [because...] Why 4: [because...] Why 5: [Root cause] 4. IMPACT ASSESSMENT Users affected: [N] Data categories exposed: [list] Financial impact: [estimate or "none identified"] Regulatory impact: [which notifications required?] 5. WHAT WORKED WELL - [e.g., Detection alert fired within 5 minutes] - [e.g., Runbook steps were clear and followed] 6. WHAT DID NOT WORK WELL - [e.g., No on-call rotation — owner was asleep] - [e.g., Logs did not have enough detail] 7. CORRECTIVE ACTIONS Action 1: [Description] | Owner: [Owner] | Due: [DATE] Action 2: [Description] | Owner: [Owner] | Due: [DATE] 8. RECURRENCE PREVENTION What specific change prevents this exact incident class from recurring? 9. SIGN-OFF Reviewed by: [Name, Date]