Incident Response Commitment
If something goes wrong, here is exactly how we will handle it.
Our Promise
Accountability Before Everything
No platform is immune to security incidents. Anyone who tells you otherwise is either lying or has not been paying attention. What separates trustworthy platforms from the rest is not whether something goes wrong — it is how they respond when it does.
This page is our public commitment. It describes exactly what we will do if a security issue is ever found, how we will communicate it, what our timeline for remediation is, and how affected users will be notified.
What Counts as an Incident
We define a security incident as any event that compromises the confidentiality, integrity, or availability of your data or our platform. This includes, but is not limited to:
Data Incidents
- Unauthorized access to user data
- Data breach or data exposure
- Unauthorized disclosure of personal information
- Loss or theft of encrypted data
- Compromise of HR or payroll records
Platform Incidents
- Unauthorized access to our systems
- Exploitation of a security vulnerability
- Malware or ransomware affecting our infrastructure
- Compromise of authentication systems
- Third-party vendor security failure affecting our users
Our Response Timeline
When a security incident is confirmed, here is what happens and when:
Immediate Containment
- Isolate affected systems to prevent further damage
- Revoke compromised credentials or access tokens
- Activate the incident response team
- Begin forensic documentation
Assessment and Scope
- Determine what data was affected and how many users are impacted
- Identify the root cause and attack vector
- Assess whether the incident is ongoing or contained
- Begin developing a remediation plan
User Notification
- Notify all affected users via email with a plain-language explanation
- Post a public notice on the platform if the incident affects the broader community
- Explain what happened, what data was affected, and what we are doing about it
- Provide specific steps users should take (e.g., change password, monitor accounts)
- Notify relevant regulatory authorities as required by law (GDPR: 72 hours, state breach laws: per jurisdiction)
Remediation and Follow-Up
- Deploy fixes for the vulnerability that was exploited
- Conduct a full post-incident review
- Publish a follow-up report explaining what happened, what we fixed, and what we changed to prevent recurrence
- Update security measures, policies, or procedures as needed
- Provide ongoing support to affected users
How We Will Communicate
When something goes wrong, silence is the worst response. Here is how we will communicate:
Direct Email to Affected Users
Every affected user will receive a direct email within 72 hours. No buried notification in a settings page. No vague blog post. A real email, from us, explaining exactly what happened and what it means for you.
Public Incident Report
For incidents affecting the broader community, we will publish a public incident report on the platform. This report will include: what happened, when it happened, what data was involved, what we did to fix it, and what we are doing to prevent it from happening again.
Plain Language — Always
We will not hide behind jargon or vague corporate language. If your data was exposed, we will say "your data was exposed." If we made a mistake, we will say "we made a mistake." You deserve clarity, not PR.
Follow-Up Updates
We will not send one notification and disappear. As we learn more, fix more, and improve our systems, we will send follow-up updates. You will know when the investigation is complete, what the final findings are, and what permanent changes we made.
What You Can Do
Security is a shared responsibility. Here is what you can do to help protect your account and our community:
Protect Your Account
- Use a strong, unique password
- Enable two-factor authentication (2FA)
- Do not share your login credentials
- Log out of shared or public devices
- Review your active sessions periodically
Report Concerns
- Report suspicious messages or accounts
- Let us know if you receive phishing attempts claiming to be from us
- Contact us immediately if you believe your account has been compromised
- If you discover a vulnerability, report it to [email protected]
Responsible Disclosure
If you are a security researcher or community member who discovers a vulnerability in our platform, we want to hear from you. We commit to:
- Acknowledging your report within 48 hours
- Keeping you informed about the remediation process
- Not pursuing legal action against researchers who report vulnerabilities responsibly
- Crediting researchers who help us improve (with their consent)
Report vulnerabilities to: [email protected]
Please include a description of the vulnerability, steps to reproduce, and any proof-of-concept. Do not access, modify, or delete other users' data during your research.
Our Track Record
As of this writing, Haunted 365 has not experienced a data breach or security incident resulting in unauthorized access to user data.
If that ever changes, this page will be updated. We will not pretend it did not happen or hope nobody notices. This community deserves better than that, and we intend to deliver it.
A Word from Dreadful Damsels
We are a small team building something for a community we care about. We do not have a PR department. We do not have a crisis communications consultant on retainer. What we have is a commitment to honesty, a deep respect for the people who trust us with their data, and the technical competence to protect it.
If something ever goes wrong, you will hear it from us first. You will hear it in plain language. And you will hear what we are doing to fix it.
That is not a policy. It is a promise.