Security Incident Response Plan
This is StrategyHub's written incident response plan, published so reviewers can read the commitments rather than ask for them. It applies to security incidents affecting the StrategyHub™ platform and the customer data it holds.
Last updated August 24, 2026 · Reports: security@strategyhub.io
Severity levels and response commitments
SEV-1 — Critical
Confirmed or strongly suspected unauthorized access to customer data, confirmed cross-tenant data exposure, or complete platform unavailability.
- Acknowledgement
- 1 hour
- Customer notification
- Affected workspace admins notified within 72 hours of confirmation, with updates at least every 72 hours until closure.
SEV-2 — High
Exploitable vulnerability with a credible path to customer data, authentication or authorization bypass, or loss of a major feature for all customers.
- Acknowledgement
- 4 business hours
- Customer notification
- Affected customers notified if data was or may have been accessed; otherwise disclosed in release notes after remediation.
SEV-3 — Moderate
Vulnerability with limited impact or requiring unusual preconditions, degraded performance, or a defect affecting a subset of workspaces.
- Acknowledgement
- 2 business days
- Customer notification
- No individual notification unless customer data was affected.
Response phases
1. Detect and report
Sources: the nightly automated QA and security sweep, centralized application and server-function error capture, platform alerts, customer reports, and external reports to security@strategyhub.io. Every report is logged with a timestamp on receipt.
2. Triage and assign severity
The engineering owner assigns a severity from the table above within the acknowledgement window, records the initial scope assessment, and opens an incident record.
3. Contain
Containment before root cause. Available actions include revoking sessions and API keys, disabling an affected integration or endpoint, tightening or temporarily hardening RLS policies, rotating credentials, and rolling back a deployment.
4. Eradicate and recover
Fix the underlying defect, verify with a targeted test plus a full security scan, restore normal service, and confirm data integrity from the audit log.
5. Notify
For any incident where customer data was accessed or may have been accessed, StrategyHub notifies affected workspace admins by email within 72 hours of confirming the incident. The notice states what happened, what data was involved, what has been done, and what the customer should do. Where a customer's contract or applicable law requires a shorter window, that window controls.
6. Post-incident review
Within 10 business days of closure: written root-cause summary, corrective actions with owners, and any policy or monitoring change. Summaries are available to affected customers on request.
Roles
StrategyHub is operated by a small engineering team. The incident owner is the StrategyHub engineering lead, who is responsible for severity assignment, containment decisions, customer notification and the post-incident review. Infrastructure-level incidents (managed Postgres, authentication service, object storage, serverless compute) are handled by the platform provider; StrategyHub relays status and impact to affected customers.
Coordinated disclosure
Researchers who report in good faith, do not access or modify other customers' data, and give us reasonable time to remediate will not be pursued. Please do not run automated scanning that degrades service for customers. Machine-readable contact details are published at /.well-known/security.txt.
Scope limits
This plan states process and notification commitments. It is not an audit, and it does not assert a published RPO/RTO or disaster recovery test evidence — see the disclosed items on the security page.
