Incident response and breach notification
Accagrity maintains an incident-response process for suspected security, privacy, availability, and integrity events. The process is designed to contain harm quickly, preserve evidence, communicate responsibly, and meet contractual and legal notification duties.
1. Report
Report suspected unauthorised access, data exposure, credential compromise, malware, or service abuse to admin@accadpro.com. Include the affected workspace, approximate time, request identifier, and safe reproduction details. Never send passwords, tokens, or unnecessary personal data in a report.
2. Triage and containment
The response team records the report, assesses severity and affected systems, preserves relevant logs, restricts compromised access, isolates affected objects or jobs, and coordinates with hosting, storage, security, email, model, and payment providers where needed. Access is limited to personnel with an operational need to know.
3. Investigation and recovery
Accagrity investigates scope, cause, affected data, persistence, and customer impact; rotates or revokes credentials where appropriate; restores safe service operation; validates document and provenance integrity; and records corrective actions. Security signals and processing failures are not silently treated as successful operations.
4. Notification
Where a confirmed incident affects customer-controlled personal data, Accagrity will notify the relevant customer without undue delay as required by the applicable DPA or law, with available information about the nature of the incident, likely consequences, affected categories, containment, and recommended actions. Customers remain responsible for assessing their own regulatory, individual, and contractual notifications. Accagrity may notify regulators or affected individuals where legally required or where the customer instructs us to do so.
5. Post-incident review
Material incidents receive a documented review covering root cause, response timing, control effectiveness, lessons learned, and preventive changes. We will provide reasonable follow-up information to affected customers while protecting confidential security details and other customers’ information.
Effective date: 3 September 2026. This overview does not replace a customer-specific incident-response plan or contractual notification terms.