Incident Response

Last updated: August 24, 2026

1. Purpose

This document provides a public summary of Universal Life Source's (ULS) incident detection and response process. It is intended to give customers and evaluators confidence that ULS can detect, respond to, and learn from security incidents.

Detailed incident response procedures and internal runbooks are maintained separately and are not publicly disclosed to avoid aiding potential attackers.

2. Incident Detection

ULS detects potential security incidents through the following mechanisms:

  • Audit logging: All security-relevant actions (logins, data changes, admin actions) are logged with timestamp, user, IP, and action details. Logs are retained for 90 days.
  • Rate limiting alerts: Unusual patterns of authentication attempts or API usage may indicate an attack.
  • Cloudflare monitoring: Cloudflare's WAF and DDoS protection provide alerts for malicious traffic patterns.
  • User reports: Users can report suspected security issues to [email protected].
  • Infrastructure monitoring: Railway provides deployment, uptime, and resource utilization monitoring.

3. Incident Classification

Severity Description Response Time
Critical Confirmed data breach, unauthorized access to user data, or complete service compromise Immediate — within 1 hour
High Security vulnerability being actively exploited, partial service compromise, or large-scale abuse Within 4 hours
Medium Identified vulnerability not yet exploited, configuration error with security implications Within 24 hours
Low Minor security concern, best-practice deviation, or informational finding Within 5 business days

4. Customer Notification

In the event of a confirmed personal data breach:

  • ULS will notify affected customers without undue delay, and in any case within 72 hours of becoming aware of the breach, in accordance with GDPR Article 34
  • Notification will be sent to the organization owner's email address
  • The notification will include: the nature of the breach, the categories and approximate number of data records concerned, the likely consequences, and the measures taken or proposed
  • If the breach is likely to result in a high risk to the rights and freedoms of individuals, ULS will also provide guidance on protective measures users can take

5. Response Process

When an incident is identified, ULS follows this process:

  1. Identify: Confirm the incident is real and assess initial scope and severity
  2. Contain: Take immediate steps to prevent further damage (disable compromised accounts, block malicious IPs, rotate credentials if needed)
  3. Investigate: Review audit logs, Cloudflare logs, and Railway deployment logs to determine root cause
  4. Notify: Notify affected customers per the notification timeline above
  5. Remediate: Apply fixes to prevent recurrence (code patches, configuration changes, access control updates)
  6. Review: Conduct a post-incident review to identify process improvements

6. Reporting a Security Issue

If you believe you have identified a security vulnerability or if you suspect your account has been compromised:

  • Email [email protected] with a description of the issue
  • If your account is compromised, change your password immediately via Logto and then contact us
  • Do not attempt to exploit or further investigate the vulnerability yourself
  • We will acknowledge receipt within 48 hours and provide a substantive response within 5 business days

7. Contact

For incident response questions or to report a security issue, contact [email protected].