Incident response (security & platform)
How Evitrus handles security reports, platform incidents, and customer notification for the managed cloud on evitrus.io.
Security contact
- Email: security@beneke-consulting.com
- Legal / privacy: legal@beneke-consulting.com
- Full page: Security contact
Severity matrix
| Severity | Definition | Examples | Initial response |
|---|---|---|---|
| S1 Critical | Confirmed breach of customer Evidence confidentiality/integrity, or total platform outage with data risk | Auth bypass, cross-tenant read, ransomware on data stores | Immediate (best effort < 1h) |
| S2 High | Significant availability loss or likely security impact under investigation | API down for all tenants, suspected key leak | Same business day |
| S3 Medium | Limited impact, workaround exists | Single-tenant degradation, non-exploited vuln in staging | Next business day |
| S4 Low | Minor / informational | Cosmetic bug with security flavor | Backlog |
Response steps
- Detect / report — monitoring, customer report, or responsible disclosure.
- Triage — assign severity; the security owner is incident lead.
- Contain — revoke keys/sessions, block access, isolate workloads as needed.
- Eradicate / recover — patch, redeploy pinned images, restore from backup if required (backup).
- Notify — see customer notification table.
- Evidence — preserve relevant org audit logs, API logs, and deploy pins; do not rewrite sealed Evidence Events.
- Postmortem — required for S1–S2 within 10 business days.
Responsible disclosure
Please report suspected vulnerabilities privately to the security address. We ask that you:
- Do not exploit beyond proof-of-concept.
- Give us a reasonable window to remediate before public disclosure.
- Avoid privacy-impacting testing against other tenants’ data.
We will acknowledge reports and keep you updated on remediation status.
Customer notification
For security incidents that affect customer Evidence Event confidentiality, integrity, or availability:
| Step | Target (beta) |
|---|---|
| Internal triage | Per severity matrix |
| Customer notice (confirmed material incident) | Within 72 hours of confirmation |
| Channel | Primary org admin email on file; status updates as needed |
Closed beta has no contractual uptime SLA. Paid SLAs accompany paid contracts.
Platform / availability incidents
Degraded API or UI is communicated to affected beta participants when the impact is material. There is no public status page yet.