4.1 What counts as an incident
A security incident is any event that compromises, or may compromise, the confidentiality or integrity of client or company information. Examples:
- A lost or stolen device used for client work
- A compromised account, or a suspicious login or password reset
- Client information sent to the wrong person or stored in an unapproved tool
- A secret or credential committed to a repository or pasted into an unapproved tool
- Malware on a device used for client work
- A security incident at a sub-processor that affects client information
4.2 Severity
| Severity | Definition | Client notification |
|---|---|---|
| High | Client information confirmed or likely exposed to an unauthorized party | Without undue delay, within 72 hours of confirmation |
| Medium | Possible exposure under investigation, or a client credential at risk | Within 72 hours if client information is affected; immediately if a client credential needs rotation |
| Low | Policy breach with no client information exposed | Not required; recorded internally |
4.3 Response steps
- Report. Whoever notices a suspected incident reports it at once to security@writechoice.io and directly to the Security Officer. Nobody waits to be certain.
- Contain. The same day: revoke or rotate affected credentials, sign the device out of all accounts, remove exposed information, and isolate the affected account or device.
- Assess. The Security Officer determines what information and which clients are affected, and sets the severity.
- Notify. Affected clients are told what happened, what information was involved, what has been done, and what they should do, within the deadlines in 4.2. Further updates follow as facts become clear.
- Recover. Restore normal work once the cause is removed and access is secured.
- Review. Within 10 business days of closure, the Security Officer writes a short post-incident review covering cause, impact, and corrective actions, and shares it with affected clients on request.
4.4 Records
Every incident, including low-severity ones, is logged with its date, description, severity, actions taken, and outcome. Logs are kept for at least three years.
4.5 Contacts
| Role | Contact |
|---|---|
| Security Officer | COO |
| Incident reporting | security@writechoice.io |
