Account → Security incident response

Security Incident Response Policy

Last updated: September 25, 2026. Reviewed every 12 months.

This policy sets out how 3AM SaaS OÜ detects, handles and reports security incidents affecting LzyReply, including personal data breaches. Report a suspected issue to security@lzyreply.com.

Roles

The founder is the incident lead and makes all decisions below.

What counts as an incident

Any event that may expose, alter, lose or block access to account or customer data: unauthorised access to the server, database, backups or admin accounts; leaked credentials or API keys; data sent to the wrong recipient; malware; or a sub-processor telling us about a breach.

Severity

LevelExampleResponse starts
CriticalPersonal data exposed or stolen; server or admin account compromisedImmediately
HighLeaked credential with no sign of misuse; vulnerability with personal data at riskWithin 4 hours
LowSuspicious activity with no data at riskWithin 2 business days

Response steps

  1. Record: open an incident log entry with time, source and what is known. Keep updating it.
  2. Contain: block the access path: rotate affected keys and tokens (Shopify, Stripe, SparkPost, OpenAI, R2, SSH), revoke sessions, and take affected features or the app offline if needed.
  3. Assess: work out what data, which merchants and which customers are affected, using the audit and server logs.
  4. Fix: remove the cause, patch, and restore clean data from encrypted backups if required.
  5. Notify (next section).
  6. Review: within 14 days, write down the cause and the changes that prevent a repeat.

Notifications

Prevention

Records

We keep a log of every incident, including ones that did not need notification, for at least 3 years.

See also our Privacy Policy and the data processing terms in our Terms of Service.