Last updated in the repository as docs/security/INCIDENT_RESPONSE.md.
What counts as an incident, what happens in the first hour, and who we tell. Published including the line saying it has never been run.
Status: DOCUMENT ONLY. This procedure has never been exercised. No drill has been run and no incident has occurred. It is recorded as an unevidenced control (CC7.4) rather than presented as a working one.
An incident is any of:
audit_events, signature_events or compliance_evidence, or a broken hash chain;A failing automated compliance check is not automatically an incident, but tenant_isolation, grant_surface, secrets_at_rest and audit_trail_intact failing are: each of those means a control that was holding has stopped.
revoke_api_key, oauth_revoke_grant, revoke_operator_token), pause the endpoint, or suspend the tenant. Each of these is a single call and each writes to the trail.audit_events and operator_events say who did what and when, per tenant.app.compliance_attest('soc2','CC7.4', …) with what happened and what changed, so the next auditor sees the procedure operating rather than merely existing.OPERATIONAL — not staffed. SignSealer is a small team and there is no on-call rota, no defined incident commander, and no out-of-hours contact. Pretending otherwise in this document would be the exact failure this document set is written to avoid.
What exists: mail.signsealer.com receives, and reports reach a person.
None performed. A procedure that has never been run is a document. The first drill should be a credential-disclosure walkthrough, because it is the one with the most steps that touch production, and it should be recorded with compliance_attest against CC7.4.

Free for the first 25 agreements a month. No card to start.