Jarvisby TheSEO
EN
Language · same pageNLNederlands/jarvis/vertrouwen/incidenten/ENEnglish (UK)/en/jarvis/trust/incidents/ESEspañolnot translated yetWe do not remember your choice and never redirect you automatically.
SEC.J02 · working method in force The reporting window for a personal data breach is set out in the data processing agreement
JarvisTrustIncidents
SEC.J02 · incident reporting processversion 0.2 · working method in force

Detect, contain, learn.

The process treats availability, confidentiality, integrity, privacy and unwanted AI behaviour as separate but linked risks.

Report a vulnerability The data processing agreementthe classification is fixed, the response time deliberately is not
FIG.01: The three levels, and the column that stays empty[##--] sheet 1/2

The classification is fixed, the response time deliberately is not

P0, P1 and P2 say how bad something is. What they do not say is how fast we respond. That column is left open because there is no service level agreement yet and no test that could back such a number up. It gets filled in as soon as there is, and not before.

~/jarvis/trust/incidents · classification[note] response not committed
levelwhat it coversfirst response
why emptyas long as a response time is not in a service level agreement and not backed by a test, a number here would say more than is true
# where the availability commitments stand is on /en/jarvis/trust/availability-and-support/
01

Triage

Record source, time, scope, tenant, suspected risk and owner.

02

Contain

Revoke access, pause a connector or isolate a component without losing evidence.

03

Communicate

Inform the customer and the parties entitled to know, without needless speculation, on a fixed update rhythm.

04

Recover

Fix the cause, test the recovery, document the impact and follow through on the improvement actions.

Spotted a vulnerability yourself? Use the route on responsible disclosure. That page says how to report, what we ask of you and what you can expect from us. This page describes what happens on our side once a report comes in.

Classification

P0 threatens several tenants, critical confidentiality or core availability. P1 has large customer impact or a likely personal data breach. P2 is limited and manageable. No response time hangs off those three levels that we would dare to call a promise: as long as it is not in a service level agreement and not backed by a test, a number here would say more than is true. What is settled is where the availability commitments stand.

Personal data breaches

As a processor, TheSEO supplies the customer with the information it has without undue delay, and internally aims to do so within twenty four hours of confirmation. That commitment sits in the chapter on personal data breaches of the data processing agreement. The controller decides on notification to its supervisory authority and to the people concerned, with support from us where that has been agreed. Which authority that is depends on where the controller sits, and it is the controller who makes that call, not us.

AI incidents

Wrong tool actions, prompt injection, source poisoning, systematic hallucination and an unexpected model change can be incidents too. They get reproducible evidence and an owner.

FIG.02: The only clock this page does name[####] sheet 2/2

Twenty four hours after confirmation, and after that it is not TheSEO who decides

With a personal data breach the route runs in three steps. We are the processor and we hand over what we know. The decision to notify sits with the controller, so with the customer. The twenty four hours is an internal target, not a statutory deadline and not a service level agreement.

~/jarvis/trust/incidents · breach.route[ok] 3 steps
# the commitment itself sits in the chapter on personal data breaches of the data processing agreement; that document leads
Section · Next stepreachable 24/7
Book a call