GoRefer Trust Center
Incident Response
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer publishes an incident-response process with severity-based targets. You can ask us for the current response plan, on-call coverage and incident records. The targets below are not a guarantee of response or resolution time.
Incident Severity Levels & Targets
Updated September 2026
| Severity | Definition | Response Target | Target Resolution | Notification Target |
|---|---|---|---|---|
| P0 – Critical | Active breach, data exfiltration, complete service outage | 15 minutes | 4 hours target | Customer + status page update within 1 hour |
| P1 – High | Significant data exposure risk, major feature outage, auth bypass | 1 hour | 24 hours target | Status page update + email to affected customers within 4 hours |
| P2 – Medium | Limited data exposure, feature degradation, suspicious activity confirmed | 4 hours | 72 hours target | Status page update within 8 hours; customer email if data is involved |
| P3 – Low | Minor vulnerability, no immediate data risk, isolated issue | 24 hours | 2-week sprint | Internal tracking; customer notification at discretion |
GDPR 72-hour notification obligation
Where GDPR applies, the controller assesses whether supervisory-authority notification is required under Article 33 and, when required, notifies without undue delay and where feasible within 72 hours of awareness. The high-risk threshold applies to data-subject notification under Article 34. As a processor, GoRefer notifies the customer without undue delay so the controller can assess its duties.
Incident Response Process
Updated September 2026
1. Detection
Automated alerts (Sentry, uptime monitors, CloudWatch)
Customer or security-researcher reports
Internal security audit findings
Threat intelligence feeds
2. Containment
Isolate affected systems
Revoke compromised credentials
Block malicious IPs
Preserve forensic evidence
3. Eradication
Root cause analysis
Patch or configuration fix
Rekey affected secrets
Re-test the affected area
4. Post-Mortem
Written post-mortem within 7 days
RCA documented in incident register
Process improvements identified
Findings shared with customers if relevant
Customer Notification Policy
Updated September 2026
What We Notify You About
Any confirmed or suspected unauthorized access to your firm's data
Data breaches affecting your clients' PII
Service outages exceeding 30 minutes
Material changes to security practices that may affect your compliance obligations
How We Notify You
Email to firm admin accounts listed on the account
In-app banner notification on next login
Status page update at status.gorefer.io
Direct phone call to firm admin for P0/P1 incidents affecting your firm
Report a Security Incident
Updated September 2026
If you believe you have discovered a security vulnerability or are aware of a security incident affecting GoRefer, please report it immediately using the form below. Our acknowledgement target is 24 hours.