WriteChoice

Incident Response Policy

Any suspected security incident is reported to the Security Officer immediately, contained the same day, and, when client information is affected, reported to the client within 72 hours of confirmation.

Version 1.0 Effective September 2026 Owner Security Officer (COO) Review At least once a year Contact security@writechoice.io

4.1 What counts as an incident

A security incident is any event that compromises, or may compromise, the confidentiality or integrity of client or company information. Examples:

  • A lost or stolen device used for client work
  • A compromised account, or a suspicious login or password reset
  • Client information sent to the wrong person or stored in an unapproved tool
  • A secret or credential committed to a repository or pasted into an unapproved tool
  • Malware on a device used for client work
  • A security incident at a sub-processor that affects client information

4.2 Severity

SeverityDefinitionClient notification
HighClient information confirmed or likely exposed to an unauthorized partyWithout undue delay, within 72 hours of confirmation
MediumPossible exposure under investigation, or a client credential at riskWithin 72 hours if client information is affected; immediately if a client credential needs rotation
LowPolicy breach with no client information exposedNot required; recorded internally

4.3 Response steps

  1. Report. Whoever notices a suspected incident reports it at once to security@writechoice.io and directly to the Security Officer. Nobody waits to be certain.
  2. Contain. The same day: revoke or rotate affected credentials, sign the device out of all accounts, remove exposed information, and isolate the affected account or device.
  3. Assess. The Security Officer determines what information and which clients are affected, and sets the severity.
  4. Notify. Affected clients are told what happened, what information was involved, what has been done, and what they should do, within the deadlines in 4.2. Further updates follow as facts become clear.
  5. Recover. Restore normal work once the cause is removed and access is secured.
  6. Review. Within 10 business days of closure, the Security Officer writes a short post-incident review covering cause, impact, and corrective actions, and shares it with affected clients on request.

4.4 Records

Every incident, including low-severity ones, is logged with its date, description, severity, actions taken, and outcome. Logs are kept for at least three years.

4.5 Contacts

RoleContact
Security OfficerCOO
Incident reportingsecurity@writechoice.io