Start free trial

This Security Incident Response Policy describes how OrderSilo detects, responds to, and recovers from security incidents affecting the OrderSilo platform, and how we communicate with customers and, where required, supervisory authorities when a security incident affects personal data. It applies to the OrderSilo website, dashboard, APIs, and underlying infrastructure, and supplements our Privacy Policy, GDPR Information, and Data Processing Agreement.

1. Purpose and scope

The purpose of this Policy is to ensure that security incidents affecting OrderSilo, its infrastructure, or Customer Data are identified, contained, investigated, and remediated in a timely and consistent manner, and that affected customers and, where legally required, supervisory authorities and individuals are notified appropriately.

This Policy applies to all OrderSilo personnel, systems, and infrastructure involved in providing the Service, and to any suspected or confirmed security incident, regardless of whether it originates internally or from a third party, including sub-processors.

2. Definitions

  • “Security incident” means any confirmed or reasonably suspected event that compromises the confidentiality, integrity, or availability of OrderSilo systems, infrastructure, or data, including unauthorized access, malware, denial-of-service attacks, and loss or theft of credentials or devices.
  • “Personal data breach” means a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, as defined under GDPR Article 4(12).

3. Roles and responsibilities

OrderSilo maintains a designated incident response function responsible for coordinating the activities below. Depending on severity, this may include:

  • Incident Lead — coordinates the response, makes containment and escalation decisions, and owns communication with affected customers.
  • Engineering / on-call responders — investigate, contain, and remediate the technical root cause.
  • Founder / management — approve customer and regulator communications, and decisions with legal or business impact.
  • External specialists (legal counsel, forensic investigators, hosting provider support) — engaged as needed for significant incidents.

4. Severity classification

Incidents are triaged and classified by severity to determine response urgency and escalation path:

  • Critical — confirmed unauthorized access to Customer Data across multiple workspaces, a platform-wide outage, or active data exfiltration. Immediate, all-hands response.
  • High — confirmed compromise limited to a single workspace or system, an exploitable vulnerability under active attack, or a suspected personal data breach. Response within hours.
  • Medium — suspicious activity requiring investigation without confirmed compromise, or an isolated vulnerability with no evidence of exploitation. Response within one business day.
  • Low — minor policy violations, false positives, or informational findings with no risk to data or availability. Handled through standard operational review.

5. Incident response lifecycle

OrderSilo follows a structured lifecycle for handling security incidents:

  • Detection and reporting — incidents are identified through automated monitoring, audit logs, vulnerability reports, or reports from customers, personnel, or third parties.
  • Triage and classification — the Incident Lead confirms the incident, assesses scope and severity, and activates the appropriate response team.
  • Containment — immediate steps are taken to limit further impact, such as revoking credentials, isolating affected systems, disabling compromised integrations, or blocking malicious traffic.
  • Investigation and eradication — the root cause is identified and removed, including patching vulnerabilities, removing unauthorized access, and validating that the threat has been eliminated.
  • Recovery — affected systems and services are restored to normal operation, with additional monitoring during the recovery period.
  • Post-incident review — a structured review is conducted to document the timeline, root cause, impact, and remediation, and to identify follow-up actions that reduce the likelihood of recurrence.

6. Notification to customers

Where a security incident results in a confirmed personal data breach affecting Customer Data that OrderSilo processes as a data processor, we will notify affected customers without undue delay, and in any event within 72 hours of confirming the breach, in line with our Data Processing Agreement.

Notifications will describe, to the extent then known, the nature of the incident, the data and data subjects likely affected, the measures taken or planned, and recommended actions for the customer, and will be updated as the investigation progresses.

Customers can reach us at any time regarding a security concern or to request incident details at hello@ordersilo.app.

7. Notification to supervisory authorities and data subjects

Where OrderSilo acts as a data controller and becomes aware of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware, in accordance with GDPR Article 33, and will notify affected individuals directly where the breach is likely to result in a high risk to them, in accordance with GDPR Article 34.

Where OrderSilo acts as a data processor, we support the customer, as data controller, in meeting its own notification obligations to supervisory authorities and data subjects, and do not notify authorities or end customers directly on the customer's behalf unless specifically agreed.

8. Reporting a suspected incident

If you believe you have discovered a security vulnerability or suspect a security incident affecting OrderSilo, please report it promptly to hello@ordersilo.app with as much detail as possible (affected system or workspace, time observed, and any supporting evidence). We aim to acknowledge reports within one business day.

9. Evidence preservation and forensics

During an active investigation, OrderSilo preserves relevant logs, system snapshots, and other evidence needed to determine root cause and impact, and restricts access to that evidence to personnel and, where engaged, external specialists directly involved in the investigation.

10. Communication during an incident

OrderSilo manages internal and external communication about an incident through the Incident Lead to ensure information shared with customers, personnel, and, where applicable, authorities is accurate, consistent, and appropriately timed. Speculative or unconfirmed details are not shared externally until verified.

11. Post-incident review and continuous improvement

After each Critical or High severity incident, OrderSilo conducts a post-incident review covering the timeline, root cause, effectiveness of the response, and concrete follow-up actions, such as additional monitoring, control changes, or process updates. Findings are used to improve this Policy and our broader security practices.

12. Testing and maintenance of this Policy

OrderSilo reviews this Policy at least annually and after any significant incident, to reflect changes in our infrastructure, sub-processors, team, or applicable law. We periodically test our incident response readiness through tabletop exercises or similar activities appropriate to our size and risk profile.

13. Related documents and contact

This Policy should be read together with our Privacy Policy, GDPR Information, and Data Processing Agreement. For questions about this Policy or to report a security concern, contact us at hello@ordersilo.app.

This Policy describes our internal processes at a summary level for transparency purposes. Certain operational and technical details are intentionally omitted to protect the effectiveness of our security controls. Related documents: Security page, GDPR Information, and Data Processing Agreement.

Start Free TrialNo credit card required