Security Incident Response Policy

The owner-led process used to assess, contain, remediate, and communicate suspected security incidents.

Effective 30 August 2026 · Version 1.0

1. Detection and identification

A suspected incident may be identified through provider notices, application errors and logs, merchant reports, or operator review. The owner records the time, affected service, reporter, and known symptoms without copying unnecessary personal data.

2. Assessment and severity

The owner determines whether confidentiality, integrity, or availability may be affected and classifies severity using the sensitivity and amount of data, number of merchants, active exploitation, financial impact, and service disruption.

3. Containment

Appropriate containment can include disabling a feature or deployment, revoking sessions, restricting access, isolating an integration, and rotating API keys, credentials, tokens, or webhook secrets through the relevant provider.

4. Investigation and remediation

Relevant application and provider records are preserved where lawful, the likely cause and affected period are established, and unsafe code, configuration, access, or data is removed or corrected. Personal data is not copied into incident notes unless necessary.

5. Recovery and validation

Service is restored only after the remediation is reviewed, credentials are rotated where needed, affected workflows are tested, and monitoring or manual checks confirm expected operation.

6. Notification

Affected merchants, Shopify, relevant service providers, regulators, or data subjects are notified when required by contract or applicable law. Notifications state known facts, likely impact, containment, and practical next steps without speculation.

7. Post-incident review

The owner documents the timeline, cause, response, effectiveness, and corrective actions, assigns follow-up owners and dates, and updates code, configuration, access, tests, or policies where appropriate.

Current operating model

This is an owner-led response process. Chargeback Recovery does not claim a 24/7 security operations centre, dedicated incident-response team, forensic retainer, penetration-test programme, SOC 2 certification, or ISO 27001 certification.

Contact

Report a suspected security incident promptly to support@aithorapp.co.uk with the subject ‘Security incident’. Do not include passwords, access tokens, payment credentials, or unnecessary customer data.

Data Processing Addendum