Trust Center
Incident Response
Last Updated: June 2026
Overview
This page describes how RequirementsHub responds to security incidents, service disruptions, and data events that may affect our customers. It is written for workspace owners, security reviewers, and anyone evaluating our security posture.
What Counts as an Incident
| Severity | Definition | Examples |
|---|---|---|
| P1 — Critical | Confirmed unauthorized access to customer data, or complete platform unavailability affecting all customers | Data breach confirmed; database exposed; authentication system compromised; platform down for all users |
| P2 — High | Significant security event with potential exposure, or major service degradation affecting a meaningful subset of customers | Suspected unauthorized access under investigation; payment processing failure; data processing pipeline halted; significant performance degradation |
| P3 — Moderate | Localized issue with limited impact, no confirmed data exposure | Single-workspace access issue; feature unavailability; degraded AI processing for a subset of requests |
Our Response Commitments
Detection & Containment
We monitor our infrastructure continuously. On detection of a potential security event, our response process begins immediately — containment takes priority over root-cause analysis.
Investigation
We investigate the scope, cause, and impact of every P1 and P2 event. This includes reviewing access logs, database audit trails, and third-party subprocessor communications.
Customer Notification
| Severity | Notification Timeline | Channel |
|---|---|---|
| P1 — Critical | Within 72 hours of confirming a breach affecting customer data | Direct email to workspace owner(s) + status page |
| P2 — High | Within 72 hours of event confirmation | Status page + email to affected workspace owners where identifiable |
| P3 — Moderate | Posted to status page; email at our discretion based on scope | Status page |
What a P1 Notification Will Include
- Date and time we became aware of the incident
- Nature of the incident and data categories potentially affected
- Estimated scope (workspaces, users, data types)
- Containment actions taken to date
- Recommended actions for your workspace (if any)
- Our point of contact for follow-up questions
Post-Incident Report
For P1 events, we commit to publishing a post-incident report within 30 days of resolution covering: timeline, root cause, impact, remediation steps taken, and process changes made to prevent recurrence. Available to affected customers on request.
Regulatory Notification
RequirementsHub operates as a data processor on behalf of customers who are data controllers. If a P1 incident involves personal data subject to GDPR or similar regulation, we will provide you with the information you need to meet your own notification obligations to supervisory authorities and data subjects. We will cooperate fully with your incident response process and provide supplementary information on request.
Service Status
Current platform status is available at: status.requirementshub.ai
Reporting a Security Vulnerability
If you believe you have found a security vulnerability in RequirementsHub, please report it responsibly:
- Email: security@requirementshub.ai
- Subject line:
[SECURITY] Brief description - Response commitment: We will acknowledge your report within 48 hours and provide a status update within 7 business days
- Our ask: Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate
- Recognition: We will credit researchers who report valid vulnerabilities in good faith, with their permission
We do not currently operate a formal bug bounty program. We intend to introduce one as the platform scales.
Scope Limitations
This incident response plan covers security events and service disruptions within RequirementsHub's control. Events originating entirely within a subprocessor's infrastructure (e.g., a Supabase or Cloudflare incident) are subject to those providers' own incident response processes. We will notify you of any subprocessor incident that affects your data as soon as we are notified by that provider.
Contact
security@requirementshub.ai · Trust Center: requirementshub.ai/trust
Last updated: June 2026