DPDPA.center — Incident Response Policy

Version: 1.0 | Effective date: 2026-06-12 Operated by: CynorSense Solutions Pvt. Ltd., India Incident contact: dpo@cynorsense.com

This policy governs how CynorSense detects, contains, and communicates security incidents and personal data breaches affecting the DPDPA.center service, consistent with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) §8(5)–(6) and the Data Processing Addendum (dpa.md).

1. Definitions

2. Detection and monitoring

3. Severity tiers

Tier Definition Examples Initial response target
SEV-1 Confirmed personal data breach or cross-tenant data exposure Tenant isolation failure; consent-ledger exfiltration; vault compromise Immediate; containment within 4 hours
SEV-2 Compromise of a single tenant or credential, or material integrity failure, no confirmed cross-tenant exposure Leaked per-tenant API secret; webhook signature bypass Within 12 hours
SEV-3 Vulnerability or availability incident with no evidence of data exposure Service outage; reported vulnerability not yet exploited Within 2 business days

4. Response steps

  1. Triage and classify — assign a severity tier and an incident lead; open an incident record with a timeline.
  2. Contain — isolate affected containers/tenants; revoke and rotate affected credentials in the OpenBao vault; invalidate affected sessions (tenant-bound sessions limit blast radius to a single site); block exploited paths at the reverse proxy if needed.
  3. Assess impact — use container logs and the append-only audit store to determine which tenants, Data Principals, and data categories are affected, and over what window.
  4. Eradicate and recover — patch the root cause, redeploy, verify via health endpoints and the verification runbook.
  5. Notify (see §5).
  6. Document — preserve evidence, the timeline, and remediation actions in the incident record.

5. Notification

6. Post-incident review

Within 10 business days of closure, the incident lead completes a post-incident review covering: root cause, detection gap, containment effectiveness, notification timeliness, and corrective actions with owners and due dates. Corrective actions are tracked to completion; recurring classes of incident trigger an update to this policy and the Security Statement.

7. Policy maintenance

This policy is reviewed at least annually, and after every SEV-1 or SEV-2 incident. Policy owner: [PLACEHOLDER: named role/person responsible, e.g., DPO / CTO of CynorSense Solutions Pvt. Ltd.]