Maintained by The Sentinel Flow

Incident response

This page describes how The Sentinel Flow classifies and responds to security incidents, how customers are notified, and how we learn from each event. It intentionally omits sensitive operational detail.

Incident classification

SEV-1

Confirmed compromise of customer data, credentials, or platform integrity. Full response team engaged.

SEV-2

Material availability or integrity impact affecting multiple customers with no data compromise.

SEV-3

Isolated or partial impact — one customer, one workflow, or degraded non-critical functionality.

SEV-4

Informational finding, near-miss, or vulnerability with no observed exploitation.

Response process

Detect

Alerts from application monitoring, provider notices, and user reports feed an on-call queue.

Triage

An incident commander classifies severity, opens a private incident record, and assigns owners.

Contain & recover

Contain first (revoke keys, disable endpoints), then restore normal operation with the smallest safe change.

Notify

Affected customers receive direct notification for SEV-1/SEV-2 impacts. Timing follows applicable contract and law.

Post-incident review

Every SEV-1/SEV-2 receives a blameless review documenting root cause, timeline, and follow-up work.

Customer notification approach

  • • We notify affected customers directly when a confirmed incident materially impacts their data or workspace.
  • • Notifications include what we know, what we do not yet know, what we are doing, and what the customer should do.
  • • Updates continue on a defined cadence until the incident is resolved.
  • • Legally required regulator notifications are handled in parallel and do not delay customer notice.

Business continuity

The platform runs on managed serverless infrastructure with managed Postgres. Daily automated backups and point-in-time recovery are provided by the infrastructure layer. Restoration procedures are exercised as part of routine engineering work; we do not publish RTO/RPO numbers we cannot contractually guarantee.

Reporting a live security concern? Use the coordinated disclosure channel.