1. Purpose
Define the process SlashLogixx follows to detect, triage, contain, eradicate, recover from, and notify customers and regulators about security incidents affecting the Spark platform or any SlashLogixx-operated product.
2. What Counts as an Incident
An incident is any confirmed or reasonably suspected event that has compromised the confidentiality, integrity, or availability of customer data, production systems, or the platform's ability to deliver service. Unverified anomalies enter triage; once triaged, they either become incidents under this policy or are closed with a written rationale.
3. Severity Classification
| Severity | Definition | Initial response | Customer notification target |
|---|---|---|---|
| SEV-1 | Confirmed unauthorized access to customer data; or complete platform outage; or active exploit. | Prioritized by severity. | As soon as confirmed and assessed. |
| SEV-2 | Material risk of compromise; partial outage affecting one or more customers; suspected exploit under investigation. | Prioritized by severity. | As soon as confirmed and assessed, if customer-impacting. |
| SEV-3 | Internal control weakness, near-miss, or single-customer incident with no data-confidentiality impact. | Prioritized by severity. | Direct to affected customer where applicable. |
4. Lifecycle
- Detect. Monitoring, log alerts, customer reports, and external advisories feed a single intake.
- Contain. Stop the bleeding. Revoke credentials, isolate hosts, block traffic, disable affected features.
- Eradicate. Remove the underlying cause — patched code, rotated key, blocked actor, removed artifact.
- Recover. Restore service from clean state and verify with health checks before re-opening user traffic.
- Notify. Customers, regulators, and (when applicable) law enforcement are notified per Section 5.
5. Customer Notification
- SlashLogixx will notify any customer whose data is reasonably believed to have been accessed, exposed, or materially impacted.
- Notifications describe what we know, what we do not yet know, what we are doing, and what action (if any) the customer should take.
- Updates are provided until the incident is closed.
6. Regulatory Notification
SlashLogixx will comply with applicable breach-notification laws including state attorneys-general statutes in the United States, GDPR Articles 33–34 where the EU is implicated, and contractually required timelines under any signed DPA or BAA. Where regulatory and customer notification timelines conflict, the shorter timeline prevails.
7. Evidence Preservation
- Logs, memory dumps, disk images, and other forensic evidence are preserved following incident closure.
8. Customer-Side Incidents (Spark Connect & Connect BYOK)
9. Communication Channel
To report a suspected security incident affecting SlashLogixx or any SlashLogixx-operated product, send details to security@slashlogixx.com.