Incident response plan

What Stickylink does when something goes wrong: how we find out, how fast we respond, when you hear from us, and how we recover. This plan applies to Stickylink Workspace, Small Business, Supply, and the consumer app, and is referenced by the Workspace Terms of Service.

Report a security issue: hello@stickylink.io. Include what you found and how to reproduce it. Please do not access another organization's data while testing. We acknowledge reports within one business day and will not pursue good-faith researchers.

Severity levels and response targets

SeverityWhat it meansAcknowledgeUpdates
SEV-1 CriticalConfirmed or suspected unauthorized access to customer data, cross-organization data exposure, or full service outage.1 hourEvery 4 hours until contained
SEV-2 HighA vulnerability that could expose data but has no evidence of exploitation, or a major feature (scanning, document release, sign-in) broken for all customers.4 hoursDaily
SEV-3 ModerateSingle-organization functional issue, degraded performance, or a low-risk vulnerability report.1 business dayAs progress is made
SEV-4 LowCosmetic issues, hardening suggestions, and informational scanner findings.5 business daysTracked in the backlog

The six phases

  1. 1. Detect

    Sources include automated database and dependency security scans, application error and runtime logging, payment-processor alerts, infrastructure provider status notices, customer reports to hello@stickylink.io, and external vulnerability disclosures.

  2. 2. Triage and declare

    The incident is assigned a severity from the table above, an owner is named, and a timeline is opened. Anything touching customer data is treated as SEV-1 until proven otherwise.

  3. 3. Contain

    Immediate actions can include revoking API keys and service credentials, invalidating sessions, rotating sticker claim tokens and document share tokens, disabling an affected feature or endpoint, tightening row-level security policies, or suspending an abusing account.

  4. 4. Eradicate and recover

    Fix the root cause, deploy, verify with a fresh security scan and targeted testing, and, where data was altered or lost, restore from the managed database backup or point-in-time recovery.

  5. 5. Notify

    Organization admins of affected workspaces are emailed without undue delay and within 72 hours of confirming an incident that compromised, or was reasonably likely to have compromised, their data. Notices state what happened, what data was involved, what we have done, and what the customer should do. Service-wide outages are communicated in-app and by email to admins.

  6. 6. Review

    Within 30 days of resolution we write a post-incident review with root cause, timeline, and corrective actions, and share it with affected organizations on request.

Notification commitment

Backups and recovery

Workspace data lives in a managed Postgres database with automated daily backups and point-in-time recovery; uploaded files are stored in redundant private object storage. Internal targets during beta are a 24-hour recovery point objective and a 24-hour recovery time objective for a full-service outage. These are internal targets, not a contractual SLA, and no uptime credits are offered during beta. Excel and PDF export are available on every plan, keep your own copies of records you cannot afford to lose.

Preventive controls

This plan is maintained by the Stickylink team and reviewed as the product changes. It describes our own process and is not an independent audit or attestation. Questions or procurement reviews: hello@stickylink.io.