Security and availability incidents must be escalated immediately.
Updated 6 October 2026
Write to codingrajan@gmail.com. For pilots, incident intake is by email. Include tenant name, affected users, timestamp, browser or Teams context, screenshots where safe, and whether customer data may be affected. Where Indian law requires it, we report a cyber security incident to CERT-In within six hours of noticing it, and from 13 May 2027 we notify the Data Protection Board of India of a personal data breach for the data we hold as data fiduciary.
Containment: disable affected access, keep the audit log and hosting logs as they are, and stop unsafe writes.Assessment: identify tenant scope, collection scope, affected users, and timeline.Communication: tell the workspace owner the confirmed impact, the mitigation, and the follow-up actions.Post-incident: add tests, rule changes, monitoring, or documentation updates before closure.