Governing policy · POL-08

Incident Management Policy

Version 1.0 · effective 13 July 2026 · owner: Jonny Allum

OwnerJonny Allum
Version1.0 · Effective 13/07/2026 · Review annually (July) and after every P1
Applies toService outages, security events, data breaches, and serious defects across all products

The step-by-step runbook is SOP-05; this policy sets the classification, duties and reporting rules that the runbook implements.

1. Severity classes

ClassDefinitionResponse
P1Platform down, data breach, tenant data integrity at risk, payments brokenDrop everything; work until mitigated; status comms to affected tenants within 4 hours
P2A module or automation line broken for multiple tenants; cron failures affecting compliance chasesSame working day
P3Single-tenant defect with workaround; cosmetic-but-embarrassingWithin 3 working days, scheduled with normal work

Security suspicion is always triaged as if P1 until shown otherwise.

2. Non-negotiable duties

  1. Log every incident — even ones nobody noticed — with timeline, cause, fix and follow-ups. The log is docs/governance/registers material an insurer, enterprise customer or acquirer will ask for.
  2. Data breaches follow POL-02 §5 clocks: tenants notified without undue delay (processor duty); ICO within 72 hours where required (controller duty); individuals where risk is high.
  3. Honesty in comms. Affected tenants get plain-language notice of what happened, what data was involved, and what is being done — no minimising.
  4. Fix forward, then learn. Every P1/P2 gets a short retrospective: what broke, why the gates didn't catch it, and which control or SOP changes as a result. An incident that changes nothing will repeat.

3. Evidence handling

During a suspected security incident: revoke first, investigate second (POL-04 §3); preserve logs (Caddy, PM2, Supabase, Stripe events) before restarting services where feasible; never destroy evidence to restore service faster unless customer data is actively being exfiltrated.

4. External reporting map

SituationReport to
Personal data breach (controller, risk threshold met)ICO ≤ 72h
Breach of tenant data (processor)The tenant, without undue delay
Card/payment anomalyStripe
Fraudulent platform useAction Fraud; provider abuse desks
← All documents & policiesQuestions? hello@jonnyai.co.uk