v1.4 policiesEffective from v1.4 general availability.
Arbiter Security Aletheia v1.4

Incident Response Standard

Effective: v1.4 general availability. Last updated: 2026-07-18.

This operator standard governs suspected compromise, tenant isolation failure, customer-data exposure, signing-key compromise, billing integrity failure, destructive availability incidents and material proof-integrity failures.

Severity

Level Examples Initial response target
P0 Active cross-tenant exposure, signing-key compromise, widespread destructive breach Immediate page and incident command
P1 Confirmed single-tenant exposure, production auth bypass, unrecoverable service outage Within 30 minutes
P2 Contained security defect, recoverable degradation, retention backlog beyond policy Same business day
P3 Low-risk weakness or operational issue without customer impact Normal engineering queue

Response sequence

  1. Declare and preserve: assign an incident commander, timestamp the event, preserve audit evidence and avoid copying customer binary content into chat.
  2. Contain: revoke affected keys/tokens, isolate machines or tenants, pause deploys, disable compromised integrations and preserve a rollback path.
  3. Assess: identify affected tenants, data classes, time window, proof and billing integrity, and whether legal notification duties apply.
  4. Eradicate and recover: repair the root cause, rotate credentials, restore from a verified backup when required, replay deletion tombstones, run migrations and retention, and validate tenant isolation before traffic.
  5. Communicate: provide accurate status without speculation. Notify affected customers and authorities within applicable legal deadlines.
  6. Learn: complete a blameless review, regression tests and tracked actions.

P0/P1 incidents block RC promotion and GA. Production rollback, database restore, Stripe webhook replay, API-key revocation and account purge are tested release gates, not first-use incident procedures.

Evidence handling

Incident records use run IDs, hashes and bounded excerpts. Raw customer binaries or proof bytes remain in approved encrypted stores only. Access is least-privilege and time-bounded. Legal holds must be explicit, approved and reviewed.

Contacts

Security intake: [email protected]. Customer support: [email protected]. The on-call escalation roster and provider emergency contacts are maintained in the restricted production runbook, not this repository.