Incident Response Standard
Effective: v1.4 general availability. Last updated: 2026-07-18.
This operator standard governs suspected compromise, tenant isolation failure, customer-data exposure, signing-key compromise, billing integrity failure, destructive availability incidents and material proof-integrity failures.
Severity
| Level | Examples | Initial response target |
|---|---|---|
| P0 | Active cross-tenant exposure, signing-key compromise, widespread destructive breach | Immediate page and incident command |
| P1 | Confirmed single-tenant exposure, production auth bypass, unrecoverable service outage | Within 30 minutes |
| P2 | Contained security defect, recoverable degradation, retention backlog beyond policy | Same business day |
| P3 | Low-risk weakness or operational issue without customer impact | Normal engineering queue |
Response sequence
- Declare and preserve: assign an incident commander, timestamp the event, preserve audit evidence and avoid copying customer binary content into chat.
- Contain: revoke affected keys/tokens, isolate machines or tenants, pause deploys, disable compromised integrations and preserve a rollback path.
- Assess: identify affected tenants, data classes, time window, proof and billing integrity, and whether legal notification duties apply.
- Eradicate and recover: repair the root cause, rotate credentials, restore from a verified backup when required, replay deletion tombstones, run migrations and retention, and validate tenant isolation before traffic.
- Communicate: provide accurate status without speculation. Notify affected customers and authorities within applicable legal deadlines.
- Learn: complete a blameless review, regression tests and tracked actions.
P0/P1 incidents block RC promotion and GA. Production rollback, database restore, Stripe webhook replay, API-key revocation and account purge are tested release gates, not first-use incident procedures.
Evidence handling
Incident records use run IDs, hashes and bounded excerpts. Raw customer binaries or proof bytes remain in approved encrypted stores only. Access is least-privilege and time-bounded. Legal holds must be explicit, approved and reviewed.
Contacts
Security intake: security@arbitersec.com. Customer support: support@arbitersec.com. The on-call escalation roster and provider emergency contacts are maintained in the restricted production runbook, not this repository.