Account ā Security incident response
Security Incident Response Policy
Last updated: September 25, 2026. Reviewed every 12 months.
This policy sets out how 3AM SaaS OĆ detects, handles and reports security incidents affecting LzyReply, including personal data breaches. Report a suspected issue to security@lzyreply.com.
Roles
The founder is the incident lead and makes all decisions below.
What counts as an incident
Any event that may expose, alter, lose or block access to account or customer data: unauthorised access to the server, database, backups or admin accounts; leaked credentials or API keys; data sent to the wrong recipient; malware; or a sub-processor telling us about a breach.
Severity
| Level | Example | Response starts |
|---|---|---|
| Critical | Personal data exposed or stolen; server or admin account compromised | Immediately |
| High | Leaked credential with no sign of misuse; vulnerability with personal data at risk | Within 4 hours |
| Low | Suspicious activity with no data at risk | Within 2 business days |
Response steps
- Record: open an incident log entry with time, source and what is known. Keep updating it.
- Contain: block the access path: rotate affected keys and tokens (Shopify, Stripe, SparkPost, OpenAI, R2, SSH), revoke sessions, and take affected features or the app offline if needed.
- Assess: work out what data, which merchants and which customers are affected, using the audit and server logs.
- Fix: remove the cause, patch, and restore clean data from encrypted backups if required.
- Notify (next section).
- Review: within 14 days, write down the cause and the changes that prevent a repeat.
Notifications
- Merchants: when their customers' data is affected, we email the account owner without undue delay and within 72 hours of confirming the breach, with what happened, the data involved, likely effects and what we are doing. We then help them notify their customers and authorities, as their processor.
- Supervisory authority: for breaches of data we control (e.g. account data) that risk people's rights, we notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware.
- Affected individuals: where the risk to them is high, we (or the merchant, as controller) tell them directly.
- Shopify: for incidents involving data obtained through Shopify's APIs, we notify Shopify without undue delay via Shopify Partner Support.
- Sub-processors: we alert any sub-processor whose systems are involved.
Prevention
- Encryption in transit (TLS) and at rest (encrypted database, per-account encrypted store credentials, encrypted backups).
- 2FA on every admin account (Shopify Partners, Stripe, Cloudflare, GitHub); server access by SSH key only.
- Least-privilege API scopes and keys limited to one purpose where the provider allows.
- Signed and verified webhooks; audit log of logins and actions.
- Nightly encrypted backups kept 30 days off-site in the EU; restore tested every 6 months.
Records
We keep a log of every incident, including ones that did not need notification, for at least 3 years.
See also our Privacy Policy and the data processing terms in our Terms of Service.