Back to Legal

Incident Response & Data Breach Policy

Last updated: January 2026

1. Security Incident Definition

A security incident is any unauthorized access, disclosure, or loss of user data including:

  • Unauthorized access to user accounts or personal data
  • Data breach exposing > 1,000 users
  • Loss of encrypted data without proper key protection
  • System compromise affecting data integrity
  • Ransomware, malware, or virus infections

2. Our Response Timeline

0-24 Hours: Investigation

Upon detection, we immediately initiate investigation, contain the incident, and determine scope/impact

24-72 Hours: User Notification

For incidents affecting data, we notify affected users with details of what was compromised and steps to take

72+ Hours: Regulatory Notification

We notify relevant authorities (GDPR supervisory authorities, state AGs, etc.) within required timeframes

7+ Days: Public Post-Mortem

We publish detailed incident report explaining what happened, how we fixed it, and prevention measures

3. User Notification Content

When notifying users of a breach, we provide:

  • Description of the incident (what data was accessed)
  • When the incident occurred
  • Recommended actions (password reset, fraud monitoring, etc.)
  • Link to Ahlan incident page with technical details
  • Contact for questions: security@ahlan.app
  • Information about available free credit monitoring (if applicable)

4. GDPR & CCPA Compliance

GDPR (EU)

  • • Notification to affected individuals within 72 hours
  • • Notification to relevant Supervisory Authority
  • • Notification to all EU users if > low risk
  • • Detailed Data Protection Impact Assessment (DPIA)

CCPA (California)

  • • Notification to affected CA residents without unreasonable delay
  • • Notification to California Attorney General if > 500 residents affected
  • • Notification to major credit reporting agencies
  • • No requirement to notify if encrypted

5. Remediation Measures

Following a breach, we implement:

  • Immediate access revocation for compromised accounts
  • Forced password reset for all affected users
  • 2FA requirement for account re-access
  • 90-day free credit monitoring (if financial data exposed)
  • Free identity theft protection (if SSN exposed)
  • Root cause analysis and prevention improvements

6. Communication Channels

For security incident inquiries:

Email: security@ahlan.app (monitored 24/7)

Incident Hotline: +1-844-AHLAN-911 (emergency only)

Status Page: status.ahlan.app

Twitter: @AhlanSecurity

7. No Liability for Third-Party Breaches

Ahlan is not liable for breaches caused by third-party service providers (AWS, payment processors, etc.), user negligence (weak passwords), or non-Ahlan systems.

8. Report a Security Vulnerability

If you discover a security vulnerability in Ahlan:

  • Email security@ahlan.app with details (don't publicly disclose)
  • Include: vulnerability description, affected systems, reproduction steps
  • Allow 72 hours for acknowledgment, 30 days for fix
  • See our Bug Bounty Program for potential rewards
  • You'll receive credit in security advisory if reported responsibly