Incident Response & Breach Notification
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
1. Scope & Definitions
This document summarizes how SimpleSecurity handles security incidents and personal data breaches affecting the platform. It is a customer-facing summary, not an internal operational runbook.
- Security incident — any event that threatens the confidentiality, integrity, or availability of the platform or the data it processes (e.g. unauthorized access attempt, service disruption, vulnerability exploitation).
- Personal data breach — a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, as defined in GDPR Art. 4(12).
2. Detection
Incidents are detected through several channels:
- AWS CloudWatch alarms on Lambda errors, API 5xx responses, dead-letter queue depth, and DynamoDB errors.
- AWS WAF logging of blocked and rate-limited requests.
- AWS CloudTrail audit trail of infrastructure and administrative API actions.
- Cognito adaptive security (compromised-credential and anomalous sign-in detection).
- Responsible-disclosure reports submitted by researchers or customers.
3. Response Process
SimpleSecurity is operated by a small team, not a 24/7 security operations center. Incidents are handled by the operating team using a defined process with assigned severities:
- Assess & classify — determine scope and assign a severity level.
- Contain — limit further impact (e.g. revoke credentials, block source, disable an affected feature).
- Eradicate & recover — remove the root cause and restore normal operation.
- Notify — inform affected customers and, where required, the supervisory authority.
- Post-incident review — document root cause and corrective actions.
4. Customer Notification
Personal data breaches
SimpleSecurity notifies affected customers of a personal data breach without undue delay and in any case within 72 hours of becoming aware of it, with the information required by GDPR Art. 33(3). The notice includes:
- The nature of the breach, including categories and approximate number of data subjects and records concerned.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and mitigate its effects.
Service incidents
Availability incidents that do not involve personal data are communicated via the status page, with email notification for material outages.
5. Post-Incident Review
After resolution, every incident is followed by a review covering root cause, corrective actions taken, and any resulting updates to our technical and organisational measures (see TOMs).
6. How to Report an Incident or Vulnerability
Report a suspected security incident or vulnerability to security@simplesecurity.se, or via /.well-known/security.txt.