Skip to content

GoRefer Trust Center

Incident Response

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

GoRefer publishes an incident-response process with severity-based targets. You can ask us for the current response plan, on-call coverage and incident records. The targets below are not a guarantee of response or resolution time.

Response policy
Incident process
Published targets

Incident Severity Levels & Targets

Updated September 2026

SeverityDefinitionResponse TargetTarget ResolutionNotification Target
P0 – CriticalActive breach, data exfiltration, complete service outage15 minutes4 hours targetCustomer + status page update within 1 hour
P1 – HighSignificant data exposure risk, major feature outage, auth bypass1 hour24 hours targetStatus page update + email to affected customers within 4 hours
P2 – MediumLimited data exposure, feature degradation, suspicious activity confirmed4 hours72 hours targetStatus page update within 8 hours; customer email if data is involved
P3 – LowMinor vulnerability, no immediate data risk, isolated issue24 hours2-week sprintInternal tracking; customer notification at discretion

GDPR 72-hour notification obligation

Where GDPR applies, the controller assesses whether supervisory-authority notification is required under Article 33 and, when required, notifies without undue delay and where feasible within 72 hours of awareness. The high-risk threshold applies to data-subject notification under Article 34. As a processor, GoRefer notifies the customer without undue delay so the controller can assess its duties.

Incident Response Process

Updated September 2026

1. Detection

  • Automated alerts (Sentry, uptime monitors, CloudWatch)

  • Customer or security-researcher reports

  • Internal security audit findings

  • Threat intelligence feeds

2. Containment

  • Isolate affected systems

  • Revoke compromised credentials

  • Block malicious IPs

  • Preserve forensic evidence

3. Eradication

  • Root cause analysis

  • Patch or configuration fix

  • Rekey affected secrets

  • Re-test the affected area

4. Post-Mortem

  • Written post-mortem within 7 days

  • RCA documented in incident register

  • Process improvements identified

  • Findings shared with customers if relevant

Customer Notification Policy

Updated September 2026

What We Notify You About

  • Any confirmed or suspected unauthorized access to your firm's data

  • Data breaches affecting your clients' PII

  • Service outages exceeding 30 minutes

  • Material changes to security practices that may affect your compliance obligations

How We Notify You

  • Email to firm admin accounts listed on the account

  • In-app banner notification on next login

  • Status page update at status.gorefer.io

  • Direct phone call to firm admin for P0/P1 incidents affecting your firm

Report a Security Incident

Updated September 2026

If you believe you have discovered a security vulnerability or are aware of a security incident affecting GoRefer, please report it immediately using the form below. Our acknowledgement target is 24 hours.

Security Disclosure Form

Report a vulnerability directly to our security team. For non-security issues, use normal support channels.

At least 20 characters. 0 entered.

Or email directly: security@gorefer.io