Detection sources
Three channels: (1) automated anomaly detection on account-access and data-access patterns, (2) error spikes flagged to on-call, (3) human report (security@koydo.app or via the bug bounty).
Hour 0 — confirm
On-call engineer + security lead converge in incident channel within 15 min of detection. Severity classification (S0 / S1 / S2). Customer-data exposure check by affected data category and account scope. The clock for the 48-hour customer notification starts at confirmation, not detection.
Hour 1 — contain
If the breach vector is identified, contain it (revoke credentials, disable affected endpoint, rotate API keys). If not yet identified, isolate the affected systems to prevent further data exposure. Document everything.
Hours 1-48 — notify
Material breaches: customer DPOs notified within 48 hours of confirmation with the full timeline + scope + which customers are affected. The notification email includes: what happened, what data was exposed, what we've done, what you should do, who to contact.
Hours 48-72 — status cadence
Status updates every 24 hours until resolved. Status page at status.koydo.app updates within 30 minutes of any state change. Customer DPOs CCed on each update.
Day 5 — post-mortem
Public post-mortem published within 5 business days. Format: what happened, root cause, what we missed, what we changed, what's still open. We publish even when post-mortems are embarrassing — published post-mortems build the kind of trust that vendor-questionnaire answers cannot.
Day 30 — verification
30-day check-in: confirm remediations held, no recurrence, no follow-on data exposure. Closed if clean; reopened if anything emerged.