Trust Center

Incident Response

Last Updated: June 2026

Overview

This page describes how RequirementsHub responds to security incidents, service disruptions, and data events that may affect our customers. It is written for workspace owners, security reviewers, and anyone evaluating our security posture.

What Counts as an Incident

SeverityDefinitionExamples
P1 — CriticalConfirmed unauthorized access to customer data, or complete platform unavailability affecting all customersData breach confirmed; database exposed; authentication system compromised; platform down for all users
P2 — HighSignificant security event with potential exposure, or major service degradation affecting a meaningful subset of customersSuspected unauthorized access under investigation; payment processing failure; data processing pipeline halted; significant performance degradation
P3 — ModerateLocalized issue with limited impact, no confirmed data exposureSingle-workspace access issue; feature unavailability; degraded AI processing for a subset of requests

Our Response Commitments

Detection & Containment

We monitor our infrastructure continuously. On detection of a potential security event, our response process begins immediately — containment takes priority over root-cause analysis.

Investigation

We investigate the scope, cause, and impact of every P1 and P2 event. This includes reviewing access logs, database audit trails, and third-party subprocessor communications.

Customer Notification

SeverityNotification TimelineChannel
P1 — CriticalWithin 72 hours of confirming a breach affecting customer dataDirect email to workspace owner(s) + status page
P2 — HighWithin 72 hours of event confirmationStatus page + email to affected workspace owners where identifiable
P3 — ModeratePosted to status page; email at our discretion based on scopeStatus page
The 72-hour notification target for P1 events aligns with GDPR Article 33 supervisory authority notification requirements. Our notification to you will not wait for a full investigation to complete — we will notify you of what we know, what we don't yet know, and what we are doing.

What a P1 Notification Will Include

  • Date and time we became aware of the incident
  • Nature of the incident and data categories potentially affected
  • Estimated scope (workspaces, users, data types)
  • Containment actions taken to date
  • Recommended actions for your workspace (if any)
  • Our point of contact for follow-up questions

Post-Incident Report

For P1 events, we commit to publishing a post-incident report within 30 days of resolution covering: timeline, root cause, impact, remediation steps taken, and process changes made to prevent recurrence. Available to affected customers on request.

Regulatory Notification

RequirementsHub operates as a data processor on behalf of customers who are data controllers. If a P1 incident involves personal data subject to GDPR or similar regulation, we will provide you with the information you need to meet your own notification obligations to supervisory authorities and data subjects. We will cooperate fully with your incident response process and provide supplementary information on request.

Service Status

Current platform status is available at: status.requirementshub.ai

Reporting a Security Vulnerability

If you believe you have found a security vulnerability in RequirementsHub, please report it responsibly:

  • Email: security@requirementshub.ai
  • Subject line: [SECURITY] Brief description
  • Response commitment: We will acknowledge your report within 48 hours and provide a status update within 7 business days
  • Our ask: Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate
  • Recognition: We will credit researchers who report valid vulnerabilities in good faith, with their permission

We do not currently operate a formal bug bounty program. We intend to introduce one as the platform scales.

Scope Limitations

This incident response plan covers security events and service disruptions within RequirementsHub's control. Events originating entirely within a subprocessor's infrastructure (e.g., a Supabase or Cloudflare incident) are subject to those providers' own incident response processes. We will notify you of any subprocessor incident that affects your data as soon as we are notified by that provider.

Contact

Last updated: June 2026