Document status: Draft for security/operations reviewLast updated: 2026-02-17Owner: Security + Operations

Notification timelines and contractual obligations are defined per environment tier and agreement scope.

Severity model

LevelDescription
Severity 1Potential high-impact service or security incident with urgent triage requirement.
Severity 2Material operational issue requiring prioritized response and coordinated containment.
Severity 3Lower-impact issue managed through scheduled remediation and follow-up.

Incident lifecycle

  1. Detection and initial triage with severity assignment.
  2. Containment actions and stakeholder coordination.
  3. Eradication and recovery with traceable execution records.
  4. Post-incident review, root-cause analysis, and corrective-action tracking.