Incident Response
1. Scope
This page covers security incidents (unauthorized access, data
exposure, malware) and availability incidents (Service-impacting
outages, degraded performance) on the production Recovery Console application
(app.dorsey-worx.com) and its dependencies. Reporting a vulnerability is
covered by the separate Security Policy.
2. Severity tiers
| Tier | Definition | Initial response |
|---|---|---|
| SEV-1 | Confirmed unauthorized access to Customer Data, full Service outage, or active data-loss event. | On-call engineer paged within 5 minutes; status page updated within 15 minutes; affected customers notified within 1 hour. |
| SEV-2 | Suspected unauthorized access, partial outage of a major surface (Today, Settings, dispatch), or material correctness bug affecting billing or dispatch. | On-call engineer engaged within 15 minutes; status page updated within 30 minutes; affected customers notified within 4 hours. |
| SEV-3 | Single-feature degradation, elevated error rates with no customer-visible outage, or a security finding that does not (yet) indicate exposure. | Triaged within 1 business day; communicated in next product update if customer-facing. |
3. Customer notification
For SEV-1 and SEV-2 incidents that affect a specific customer’s data, we notify the operator account owner by email at the address on file. The notification includes:
- What happened, in plain language.
- What data, if any, was affected.
- What we’ve done to contain the incident.
- What we’re doing to prevent recurrence.
- What action, if any, the customer needs to take.
Where state law (e.g. California breach notification: Cal. Civ. Code § 1798.82) imposes additional notification timelines or content requirements on the customer as controller, we provide whatever information the customer needs to meet those requirements within the statutory window.
4. Status page
Service availability incidents are posted to the public status page. Subscribers can receive email updates per incident. (Status-page hosting is being finalized; in the interim availability incidents are communicated by email plus the in-app banner.)
5. Recovery objectives (RTO / RPO)
For the production application we commit to a 4-hour RTO (Recovery Time Objective) and a 1-hour RPO (Recovery Point Objective). These are the maximum tolerable values; capability in normal operating conditions is significantly better. The full statement — including the mechanics that back the commitments, the quarterly restore-drill cadence, and what's explicitly not commitment-grade today — is in our internal RTO/RPO + Disaster Recovery document, available to prospects and auditors on request via security@dorsey-worx.com.
6. Post-mortem
For every SEV-1 and SEV-2 incident we publish a post-mortem within 7 calendar days of resolution. Post-mortems are blameless and include a timeline, root cause(s), customer impact, what we did right, what we did wrong, and the concrete remediation work that followed. Post-mortems are emailed to affected customers.
7. Forensic preservation
For any incident classified SEV-1 or SEV-2 with a security component, we preserve logs, snapshots, and other evidence for at least 365 days, isolated from normal retention so it cannot be auto-deleted before an investigation completes.
8. Customer cooperation
If we suspect an incident originates inside a customer’s account (compromised operator credentials, abuse of the Service), we will reach out to the operator on the contact email on file before taking any action that would suspend or limit access, unless the threat is severe enough that an immediate suspension is required to protect other customers or end-recipients.
9. Reporting an incident to us
- Security: security@dorsey-worx.com (PGP key on the Security Policy page).
- Outage / availability: support@dorsey-worx.com — we monitor this 24/7.
- SMS abuse: abuse@dorsey-worx.com.