Incident Response Plan

Last updated: August 6, 2026 · Memcode AI, Inc.

1. Purpose

This plan establishes procedures for identifying, containing, eradicating, and recovering from security incidents that may affect the confidentiality, integrity, or availability of customer data processed by Memcode.

2. Scope

This plan covers all components of the Memcode platform including the web application, API layer, model gateway, database, file storage, and authentication services.

3. Incident Classification

Severity 1 — Critical

Confirmed unauthorized access to customer data. Data exfiltration. Compromised authentication system or provider key vault. Active exploitation of a vulnerability.

Severity 2 — High

Suspected unauthorized access. Compromised credentials. Vulnerability discovered with known exploit. Service disruption affecting multiple users.

Severity 3 — Medium

Failed intrusion attempt. Vulnerability discovered without known exploit. Single-user account compromise. Policy violation.

Severity 4 — Low

Suspicious activity without confirmed impact. Minor policy deviation. Informational security alert from monitoring.

4. Response Procedures

Phase 1: Detection & Reporting

  • Monitor application and gateway logs for anomalous activity patterns.
  • Review error logs and rate limiting alerts.
  • Report suspected incidents immediately to tim@memcode.ai.
  • Log initial findings including time of detection, affected systems, and scope.

Phase 2: Containment

  • Severity 1-2: Immediately revoke affected user sessions. Rotate compromised keys and tokens, including gateway organization keys. If necessary, halt gateway traffic to stop all model access.
  • Severity 3-4: Disable affected user accounts. Block suspicious IP addresses via rate limiting configuration.
  • Preserve application and gateway logs for forensic analysis.

Phase 3: Eradication

  • Identify root cause through log analysis.
  • Patch vulnerability or close attack vector.
  • Rotate all potentially compromised credentials, including customer-supplied provider keys in the secrets vault, with notification to affected customers.
  • Verify fix through testing before restoring service.

Phase 4: Recovery

  • Restore service from known-good state.
  • Monitor closely for recurrence with increased log review frequency.
  • Re-enable affected user accounts after credential reset.

Phase 5: Post-Incident

  • Document incident timeline, impact, root cause, and remediation actions.
  • Update this plan with lessons learned.
  • Update the POA&M if new security gaps were identified.

5. Notification Requirements

SeverityInternal NotificationExternal Notification
Sev 1 (Critical)ImmediatelyAffected customers within 72 hours.
Sev 2 (High)Within 4 hoursAffected customers within 72 hours if customer data was impacted.
Sev 3 (Medium)Within 24 hoursAs needed based on impact assessment.
Sev 4 (Low)Next business dayNot required unless escalated.

6. Contact

Report security incidents to tim@memcode.ai.