Incident Response Plan
Last updated: August 6, 2026 · Memcode AI, Inc.
1. Purpose
This plan establishes procedures for identifying, containing, eradicating, and recovering from security incidents that may affect the confidentiality, integrity, or availability of customer data processed by Memcode.
2. Scope
This plan covers all components of the Memcode platform including the web application, API layer, model gateway, database, file storage, and authentication services.
3. Incident Classification
Severity 1 — Critical
Confirmed unauthorized access to customer data. Data exfiltration. Compromised authentication system or provider key vault. Active exploitation of a vulnerability.
Severity 2 — High
Suspected unauthorized access. Compromised credentials. Vulnerability discovered with known exploit. Service disruption affecting multiple users.
Severity 3 — Medium
Failed intrusion attempt. Vulnerability discovered without known exploit. Single-user account compromise. Policy violation.
Severity 4 — Low
Suspicious activity without confirmed impact. Minor policy deviation. Informational security alert from monitoring.
4. Response Procedures
Phase 1: Detection & Reporting
- Monitor application and gateway logs for anomalous activity patterns.
- Review error logs and rate limiting alerts.
- Report suspected incidents immediately to tim@memcode.ai.
- Log initial findings including time of detection, affected systems, and scope.
Phase 2: Containment
- Severity 1-2: Immediately revoke affected user sessions. Rotate compromised keys and tokens, including gateway organization keys. If necessary, halt gateway traffic to stop all model access.
- Severity 3-4: Disable affected user accounts. Block suspicious IP addresses via rate limiting configuration.
- Preserve application and gateway logs for forensic analysis.
Phase 3: Eradication
- Identify root cause through log analysis.
- Patch vulnerability or close attack vector.
- Rotate all potentially compromised credentials, including customer-supplied provider keys in the secrets vault, with notification to affected customers.
- Verify fix through testing before restoring service.
Phase 4: Recovery
- Restore service from known-good state.
- Monitor closely for recurrence with increased log review frequency.
- Re-enable affected user accounts after credential reset.
Phase 5: Post-Incident
- Document incident timeline, impact, root cause, and remediation actions.
- Update this plan with lessons learned.
- Update the POA&M if new security gaps were identified.
5. Notification Requirements
| Severity | Internal Notification | External Notification |
|---|---|---|
| Sev 1 (Critical) | Immediately | Affected customers within 72 hours. |
| Sev 2 (High) | Within 4 hours | Affected customers within 72 hours if customer data was impacted. |
| Sev 3 (Medium) | Within 24 hours | As needed based on impact assessment. |
| Sev 4 (Low) | Next business day | Not required unless escalated. |
6. Contact
Report security incidents to tim@memcode.ai.