Incident response plan
What Stickylink does when something goes wrong: how we find out, how fast we respond, when you hear from us, and how we recover. This plan applies to Stickylink Workspace, Small Business, Supply, and the consumer app, and is referenced by the Workspace Terms of Service.
Severity levels and response targets
| Severity | What it means | Acknowledge | Updates |
|---|---|---|---|
| SEV-1 Critical | Confirmed or suspected unauthorized access to customer data, cross-organization data exposure, or full service outage. | 1 hour | Every 4 hours until contained |
| SEV-2 High | A vulnerability that could expose data but has no evidence of exploitation, or a major feature (scanning, document release, sign-in) broken for all customers. | 4 hours | Daily |
| SEV-3 Moderate | Single-organization functional issue, degraded performance, or a low-risk vulnerability report. | 1 business day | As progress is made |
| SEV-4 Low | Cosmetic issues, hardening suggestions, and informational scanner findings. | 5 business days | Tracked in the backlog |
The six phases
- 1. Detect
Sources include automated database and dependency security scans, application error and runtime logging, payment-processor alerts, infrastructure provider status notices, customer reports to hello@stickylink.io, and external vulnerability disclosures.
- 2. Triage and declare
The incident is assigned a severity from the table above, an owner is named, and a timeline is opened. Anything touching customer data is treated as SEV-1 until proven otherwise.
- 3. Contain
Immediate actions can include revoking API keys and service credentials, invalidating sessions, rotating sticker claim tokens and document share tokens, disabling an affected feature or endpoint, tightening row-level security policies, or suspending an abusing account.
- 4. Eradicate and recover
Fix the root cause, deploy, verify with a fresh security scan and targeted testing, and, where data was altered or lost, restore from the managed database backup or point-in-time recovery.
- 5. Notify
Organization admins of affected workspaces are emailed without undue delay and within 72 hours of confirming an incident that compromised, or was reasonably likely to have compromised, their data. Notices state what happened, what data was involved, what we have done, and what the customer should do. Service-wide outages are communicated in-app and by email to admins.
- 6. Review
Within 30 days of resolution we write a post-incident review with root cause, timeline, and corrective actions, and share it with affected organizations on request.
Notification commitment
- • Confirmed compromise of your organization's data: organization admins emailed within 72 hours of confirmation.
- • Post-incident summary available within 30 days of resolution, on request.
- • Because Workspace prohibits PHI, cardholder data, ITAR, classified, and clinical-trial records, we are not a HIPAA business associate and do not file regulator notices for you. We will give you the facts you need to make your own.
- • Keep a reachable admin email on the account, that address is how we reach you in an incident.
Backups and recovery
Workspace data lives in a managed Postgres database with automated daily backups and point-in-time recovery; uploaded files are stored in redundant private object storage. Internal targets during beta are a 24-hour recovery point objective and a 24-hour recovery time objective for a full-service outage. These are internal targets, not a contractual SLA, and no uptime credits are offered during beta. Excel and PDF export are available on every plan, keep your own copies of records you cannot afford to lose.
Preventive controls
- • TLS in transit, provider-managed encryption at rest
- • Row-level security scoping every workspace table to an organization
- • Roles stored separately from profiles and checked server-side
- • Domain-locked organizations with admin approval for new members
- • Private file buckets served through short-lived signed URLs
- • Append-only audit log of reads, edits, releases, and approvals
- • Optional TOTP multi-factor authentication for members
- • Automated database and dependency security scans on an ongoing basis
- • Card data isolated to our PCI-compliant payment processor
This plan is maintained by the Stickylink team and reviewed as the product changes. It describes our own process and is not an independent audit or attestation. Questions or procurement reviews: hello@stickylink.io.
