Incident Response Policy
Last updated: January 5, 2026
1. Purpose and Scope
This Incident Response Policy establishes procedures for identifying, responding to, and recovering from security incidents affecting RECRUITED's systems, data, and users. This policy applies to all systems, data, and personnel involved in the operation of the RECRUITED platform, including our Gmail API integration and user data.
2. Incident Classification
Security incidents are classified by severity to ensure appropriate response:
- Critical (P1): Active data breach, unauthorized access to user data or Gmail tokens, complete service outage, ransomware attack. Response time: Immediate (within 1 hour).
- High (P2): Attempted unauthorized access, significant vulnerability discovered, partial service degradation affecting user authentication. Response time: Within 4 hours.
- Medium (P3): Suspicious activity detected, minor vulnerability identified, isolated system issues. Response time: Within 24 hours.
- Low (P4): Policy violations, minor misconfigurations, informational security events. Response time: Within 72 hours.
3. Incident Response Team
The Incident Response Team consists of:
- Incident Commander: Coordinates overall response, makes critical decisions, manages communications
- Technical Lead: Leads technical investigation and remediation efforts
- Communications Lead: Manages internal and external communications, including user notifications
- Legal/Compliance: Advises on regulatory requirements and legal obligations
Contact the security team at: security@recruitedcrm.com
4. Detection and Reporting
4.1 Detection Methods
- Automated monitoring and alerting systems
- Log analysis and anomaly detection
- User reports and support tickets
- Third-party security notifications (Google, infrastructure providers)
- Vulnerability disclosure reports
4.2 Internal Reporting
All employees and contractors must immediately report suspected security incidents to the security team. Reports should include: what was observed, when it occurred, systems or data involved, and any actions already taken.
5. Response Procedures
5.1 Initial Response (First 1-4 hours)
- Activate Incident Response Team
- Assess scope and severity of incident
- Begin documentation in incident log
- Implement immediate containment measures
- Preserve evidence and system logs
5.2 Containment
- Isolate affected systems if necessary
- Revoke compromised credentials or OAuth tokens
- Block malicious IP addresses or accounts
- Implement temporary security controls
5.3 Eradication and Recovery
- Remove malicious code or unauthorized access
- Patch vulnerabilities
- Restore systems from clean backups if needed
- Verify system integrity before returning to production
- Gradually restore services with enhanced monitoring
6. Communication Protocol
6.1 User Notification
In the event of a data breach affecting user data:
- Affected users will be notified within 72 hours of breach confirmation
- Notification will include: what happened, what data was involved, what we're doing about it, and what users should do
- Notifications will be sent via email and in-app messaging
6.2 Regulatory Notification
We will notify relevant regulatory authorities as required by applicable law, including but not limited to state data breach notification laws.
6.3 Third-Party Notification
Google will be notified of any incidents affecting Gmail API data or OAuth tokens in accordance with Google API Terms of Service requirements.
7. Post-Incident Review
Following incident resolution:
- Conduct root cause analysis within 5 business days
- Document lessons learned and remediation actions
- Update security controls and procedures as needed
- Provide incident summary to leadership
- Schedule follow-up review to verify remediation effectiveness
8. Evidence Preservation
All evidence related to security incidents will be preserved for a minimum of one year, including:
- System and application logs
- Network traffic captures
- Forensic images of affected systems
- Incident response documentation
- Communications related to the incident
9. Policy Review
This Incident Response Policy is reviewed and updated annually, or following any significant security incident, to ensure its continued effectiveness and alignment with industry best practices.
10. Contact Information
For security incidents or questions about this policy, contact us at:
- Security Team: security@recruitedcrm.com
- General Support: contact@recruitedcrm.com