Operations

Incident response

Follow the Incident response operator checklist with on-call. Never wipe databases during an incident.

  • SEV1: authority exposure, revocation bypass, or live billing corruption.
  • Preserve logs and commit SHAs; freeze live unlocks if authority is in doubt.
  • Verify trust boundaries and deny unauthorised access while investigating.
  • Write a timeline and update the runbook after action.