Incident Response
Reporting a security issue
Section titled “Reporting a security issue”To report a security vulnerability or suspected breach:
- Email: [email protected]
- Subject:
Security report: [brief description] - Include: steps to reproduce, affected component, and your contact information
We treat all security reports as confidential. Please do not disclose the issue publicly before we have had a chance to investigate and respond.
What happens after you report
Section titled “What happens after you report”| Step | Timeline |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial triage | Within 5 business days |
| Status update | Within 10 business days |
| Resolution | Depends on severity |
Severity levels
Section titled “Severity levels”| Level | Examples | Target resolution |
|---|---|---|
| Critical | Data breach, authentication bypass | 24–72 hours |
| High | Privilege escalation, data exposure | 7 days |
| Medium | Information disclosure, CSRF | 30 days |
| Low | Minor issues, hardening improvements | 90 days |
Customer notification
Section titled “Customer notification”If a security incident affects customer data, Claryn will notify affected organizations by email within 72 hours of confirmation. Notifications include:
- What happened
- What data was affected
- What Claryn has done or is doing
- Recommended actions for affected customers
Regulatory reporting
Section titled “Regulatory reporting”Claryn will assist customers in meeting their own regulatory notification obligations (e.g., LGPD, GDPR) where applicable.