Legal & trust
Incident Response Policy
How security incidents are detected, contained and disclosed.
Last updated · August 2026
1. Purpose
This Incident Response Policy defines the procedures for detecting, responding to, and recovering from security incidents affecting the Sales Advisor platform, its infrastructure, or customer data.
2. Incident Classification
Security incidents are classified by severity:
- Critical: Confirmed data breach, unauthorized access to customer data, active exploitation of a vulnerability, or complete service outage.
- High: Detected intrusion attempt, potential data exposure, partial service disruption, or compromise of authentication systems.
- Medium: Suspicious activity patterns detected by anomaly detection (SQL injection attempts, path traversal, XSS), brute-force attack campaigns, or scanning tool activity.
- Low: Minor policy violations, failed login attempts below threshold, or informational security events.
3. Detection
Sales Advisor employs the following detection mechanisms:
- Automated Security Logging: Real-time logging of all security events with anomaly pattern matching for path traversal, SQL injection, XSS, shell injection, null byte injection, and known scanning tools.
- Brute-Force Detection: Database-backed tracking of failed login attempts with automatic account lockout after 5 failed attempts.
- Health Monitoring: Continuous health checks on database, cache, and AI service dependencies with status reporting.
- Audit Trail: Immutable logging of all data modifications with before/after values for forensic analysis.
- Session Monitoring: Tracking of active sessions with automatic cleanup of expired or inactive sessions.
4. Response Procedures
4.1 Immediate Actions (Within 1 Hour)
- Assess the scope and severity of the incident using security logs and audit trail.
- Contain the threat by disabling affected accounts, revoking compromised sessions, or blocking malicious IP addresses.
- Preserve evidence by securing relevant security logs, audit trail entries, and system state.
4.2 Investigation (Within 24 Hours)
- Determine the root cause using security logs, audit trail data, and system analysis.
- Identify all affected systems, accounts, and data.
- Document the timeline of events and actions taken.
4.3 Notification (Within 72 Hours)
- Notify affected customers within 72 hours of confirmed data breach, in compliance with GDPR Article 33 and applicable privacy laws.
- Provide details of the breach including nature, scope, likely consequences, and remediation measures.
- Notify relevant supervisory authorities as required by applicable law.
5. Recovery
- Restore affected systems from clean backups via Neon's point-in-time recovery.
- Force password resets for compromised accounts.
- Invalidate all active sessions and require re-authentication.
- Rotate encryption keys if key compromise is suspected.
- Deploy patches or configuration changes to prevent recurrence.
6. Post-Incident Review
After each significant incident, a post-incident review is conducted to document lessons learned, update security controls, and revise this policy if necessary. Review findings are retained for a minimum of 12 months.
7. Contact
To report a security incident or vulnerability, contact info@salesadvisor.ca.