Incident Response
Aventora maintains incident response procedures to detect, respond to, and recover from security and privacy incidents affecting customer data and platform availability.
For policy requirements, see the Personal Data Privacy & Protection Policy and Data Classification and Handling Policy.
Incident response phases
| Phase | Activities |
|---|---|
| Detection and reporting | Monitoring, employee reporting channels, customer notifications of suspected issues |
| Triage and classification | Severity assessment; identification of affected data and customers |
| Containment | Access revocation, credential rotation, service isolation as needed |
| Investigation | Root cause analysis, evidence preservation, log review |
| Notification | Customer notification and regulatory notification where required by law or contract |
| Recovery | Restoration of services; validation of control effectiveness |
| Post-incident review | Lessons learned, remediation tracking, policy updates |
Privacy breach management
Where an incident involves unauthorized access, disclosure, or loss of personal information, Aventora:
- Investigates promptly and documents findings
- Notifies affected customers without undue delay where required by agreement or law
- Cooperates with customers in fulfilling data subject and regulator notifications where Aventora acts as Processor
- Implements corrective measures to reduce recurrence risk
Notification timelines align with applicable legal requirements and contractual obligations.
Technical capabilities
Incident response is supported by:
- Centralized logging with controlled retention periods across platform services
- Request tracing and structured error handling for operational diagnostics
- Configurable alert recipients for security-relevant operational events
See Logging and Audit.
Customer cooperation
Customers are responsible for cooperating with Aventora during security and privacy incidents affecting customer data, including:
- Providing timely contact information for incident notification
- Assisting with data subject communications where the customer acts as Controller
- Preserving relevant evidence on customer-managed systems where applicable
Reporting security concerns
To report a suspected security incident or vulnerability:
For enterprise security inquiries: sales@aventora.ai
Related documentation
- Logging and Audit
- Vulnerability Management
- Business Continuity
- Disaster Recovery Tabletop Exercise
- Information Security Risk Management Policy (security incidents trigger risk-register review)
- Privacy Notice
Changelog
| Date | Change |
|---|---|
| 2026-08-11 | Linked corrected tabletop report date (August 11, 2026 / BCP-TT-2026-07). |
| 2026-08-01 | Linked Disaster Recovery Tabletop Exercise; removed duplicate Business Continuity related link. |
| 2026-07-27 | Linked Business Continuity (annual BCP tabletop requirement). |
| 2026-07-27 | Linked Information Security Risk Management Policy (incident-driven risk review). |
| 2026-07-06 | Initial publication of incident response overview. |