| Owner | Jonny Allum |
| Version | 1.0 · Effective 13/07/2026 · Review annually (July) and after every P1 |
| Applies to | Service outages, security events, data breaches, and serious defects across all products |
The step-by-step runbook is SOP-05; this policy sets the classification, duties and reporting rules that the runbook implements.
1. Severity classes
| Class | Definition | Response |
|---|---|---|
| P1 | Platform down, data breach, tenant data integrity at risk, payments broken | Drop everything; work until mitigated; status comms to affected tenants within 4 hours |
| P2 | A module or automation line broken for multiple tenants; cron failures affecting compliance chases | Same working day |
| P3 | Single-tenant defect with workaround; cosmetic-but-embarrassing | Within 3 working days, scheduled with normal work |
Security suspicion is always triaged as if P1 until shown otherwise.
2. Non-negotiable duties
- Log every incident — even ones nobody noticed — with timeline, cause, fix and follow-ups. The log is
docs/governance/registersmaterial an insurer, enterprise customer or acquirer will ask for. - Data breaches follow POL-02 §5 clocks: tenants notified without undue delay (processor duty); ICO within 72 hours where required (controller duty); individuals where risk is high.
- Honesty in comms. Affected tenants get plain-language notice of what happened, what data was involved, and what is being done — no minimising.
- Fix forward, then learn. Every P1/P2 gets a short retrospective: what broke, why the gates didn't catch it, and which control or SOP changes as a result. An incident that changes nothing will repeat.
3. Evidence handling
During a suspected security incident: revoke first, investigate second (POL-04 §3); preserve logs (Caddy, PM2, Supabase, Stripe events) before restarting services where feasible; never destroy evidence to restore service faster unless customer data is actively being exfiltrated.
4. External reporting map
| Situation | Report to |
|---|---|
| Personal data breach (controller, risk threshold met) | ICO ≤ 72h |
| Breach of tenant data (processor) | The tenant, without undue delay |
| Card/payment anomaly | Stripe |
| Fraudulent platform use | Action Fraud; provider abuse desks |