ncdLabs
Incident response

Incident management and response policy

This policy covers security incidents and significant service outages affecting systems operated by NorthCoast DevOps LLC (ncdLabs).

Definitions

Roles

Reporting channels

Response process

  1. Detect — monitoring alerts, customer reports, partner notices, or internal discovery.
  2. Triage — confirm scope, severity, and whether customer data or credentials may be involved.
  3. Contain — revoke or rotate secrets, disable compromised integrations, isolate systems, or roll back as appropriate.
  4. Eradicate and recover — remove the cause, restore service, verify integrity of critical data paths.
  5. Communicate — notify affected customers when required by contract, law, or material impact; use accurate, timely updates via help@ or agreed channels.
  6. Learn — record timeline, root cause, and corrective actions; track follow-ups to completion.

Severity (guidance)

Evidence and retention

Incident notes, relevant logs, and remediation artifacts are retained long enough for investigation and contractual or legal obligations, then disposed of under the data retention and protection policy.

Last updated: September 27, 2026

NorthCoast DevOps LLC (ncdLabs)