1. Security Incident Definition A security incident is any unauthorized access, disclosure, or loss of user data including:
Unauthorized access to user accounts or personal data Data breach exposing > 1,000 users Loss of encrypted data without proper key protection System compromise affecting data integrity Ransomware, malware, or virus infections 2. Our Response Timeline 0-24 Hours: Investigation Upon detection, we immediately initiate investigation, contain the incident, and determine scope/impact
24-72 Hours: User Notification For incidents affecting data, we notify affected users with details of what was compromised and steps to take
72+ Hours: Regulatory Notification We notify relevant authorities (GDPR supervisory authorities, state AGs, etc.) within required timeframes
7+ Days: Public Post-Mortem We publish detailed incident report explaining what happened, how we fixed it, and prevention measures
3. User Notification Content When notifying users of a breach, we provide:
Description of the incident (what data was accessed) When the incident occurred Recommended actions (password reset, fraud monitoring, etc.) Link to Ahlan incident page with technical details Contact for questions: security@ahlan.app Information about available free credit monitoring (if applicable) 4. GDPR & CCPA Compliance GDPR (EU) • Notification to affected individuals within 72 hours • Notification to relevant Supervisory Authority • Notification to all EU users if > low risk • Detailed Data Protection Impact Assessment (DPIA) CCPA (California) • Notification to affected CA residents without unreasonable delay • Notification to California Attorney General if > 500 residents affected • Notification to major credit reporting agencies • No requirement to notify if encrypted 5. Remediation Measures Following a breach, we implement:
Immediate access revocation for compromised accounts Forced password reset for all affected users 2FA requirement for account re-access 90-day free credit monitoring (if financial data exposed) Free identity theft protection (if SSN exposed) Root cause analysis and prevention improvements 6. Communication Channels For security incident inquiries:
Email: security@ahlan.app (monitored 24/7)
Incident Hotline: +1-844-AHLAN-911 (emergency only)
Status Page: status.ahlan.app
Twitter: @AhlanSecurity
7. No Liability for Third-Party Breaches Ahlan is not liable for breaches caused by third-party service providers (AWS, payment processors, etc.), user negligence (weak passwords), or non-Ahlan systems.
8. Report a Security Vulnerability If you discover a security vulnerability in Ahlan:
Email security@ahlan.app with details (don't publicly disclose) Include: vulnerability description, affected systems, reproduction steps Allow 72 hours for acknowledgment, 30 days for fix See our Bug Bounty Program for potential rewards You'll receive credit in security advisory if reported responsibly