Skip to main content

Incident Response

Aventora maintains incident response procedures to detect, respond to, and recover from security and privacy incidents affecting customer data and platform availability.

For policy requirements, see the Personal Data Privacy & Protection Policy and Data Classification and Handling Policy.


Incident response phases

PhaseActivities
Detection and reportingMonitoring, employee reporting channels, customer notifications of suspected issues
Triage and classificationSeverity assessment; identification of affected data and customers
ContainmentAccess revocation, credential rotation, service isolation as needed
InvestigationRoot cause analysis, evidence preservation, log review
NotificationCustomer notification and regulatory notification where required by law or contract
RecoveryRestoration of services; validation of control effectiveness
Post-incident reviewLessons learned, remediation tracking, policy updates

Privacy breach management

Where an incident involves unauthorized access, disclosure, or loss of personal information, Aventora:

  • Investigates promptly and documents findings
  • Notifies affected customers without undue delay where required by agreement or law
  • Cooperates with customers in fulfilling data subject and regulator notifications where Aventora acts as Processor
  • Implements corrective measures to reduce recurrence risk

Notification timelines align with applicable legal requirements and contractual obligations.


Technical capabilities

Incident response is supported by:

  • Centralized logging with controlled retention periods across platform services
  • Request tracing and structured error handling for operational diagnostics
  • Configurable alert recipients for security-relevant operational events

See Logging and Audit.


Customer cooperation

Customers are responsible for cooperating with Aventora during security and privacy incidents affecting customer data, including:

  • Providing timely contact information for incident notification
  • Assisting with data subject communications where the customer acts as Controller
  • Preserving relevant evidence on customer-managed systems where applicable

Reporting security concerns

To report a suspected security incident or vulnerability:

security@aventora.ai

For enterprise security inquiries: sales@aventora.ai



Changelog

DateChange
2026-08-11Linked corrected tabletop report date (August 11, 2026 / BCP-TT-2026-07).
2026-08-01Linked Disaster Recovery Tabletop Exercise; removed duplicate Business Continuity related link.
2026-07-27Linked Business Continuity (annual BCP tabletop requirement).
2026-07-27Linked Information Security Risk Management Policy (incident-driven risk review).
2026-07-06Initial publication of incident response overview.