Organiz Docs
Trust & Legal

Security incident response policy

How Organiz prevents, detects, and responds to security incidents.

Effective date: September 26, 2026 Last updated: September 26, 2026

This policy describes how Organiz identifies, contains, and responds to security incidents, and what clients can expect if one affects their data.

What counts as a security incident

A security incident is any confirmed or reasonably suspected event that compromises the confidentiality, integrity, or availability of client or member data, or of the systems that handle it. Examples: unauthorized access to an account or organization's data, exposure of an encrypted credential (like a connected integration's API key), or a vulnerability that could let one organization access another's data.

We classify incidents by severity:

SeverityDefinitionExample
CriticalConfirmed unauthorized access to personal data, or a live exploit affecting multiple organizationsA bug lets one org read another org's member data
HighA vulnerability with clear exploit potential, not yet confirmed as exploitedAn access-control gap discovered in review, before any exploitation
ModerateA security-relevant defect with limited or no data exposureA missing input validation check with no evidence of misuse
LowA hardening opportunity with no direct exposureA defense-in-depth improvement

Our standing security practice

Security review isn't a periodic audit at Organiz, it's part of how every change ships. Every change that touches authentication, authorization, or data access is checked against a documented security checklist before it's considered done, covering things like: is the caller authenticated and authorized for this specific resource, is user input validated, are error messages free of internal detail, is a connected integration's credential encrypted at rest and never logged.

When a security issue is found, whether in review, in testing, or reported from outside, we document the root cause and the fix, not just patch the symptom, so the same class of issue doesn't recur elsewhere in the codebase. This is a real, running practice: our internal security log tracks each issue found this way, its root cause, and the general lesson it produced.

Roles and responsibilities

RolePersonResponsibility
Incident ownerSaulo Oliveira, CTO (saulo@organiz.org)Leads the response: severity, containment, fix, and review
Escalation contactKedar Reddy, Founder & CEO (kedar@organiz.org)Owns client communication and steps in if the owner can't be reached

Reports sent to security@organiz.org reach both.

Detection and reporting

Incidents can surface through our own review process, automated checks, client reports, or independent security research. Anyone, staff, client, or independent researcher, can report a suspected issue to security@organiz.org, and we treat every report as credible until we've confirmed otherwise.

Response process

  1. Identify. Confirm whether a reported or detected issue is a real incident, and assign it a severity.
  2. Contain. Limit the exposure immediately, this might mean disabling a feature, rotating a credential, or blocking an access path, before a full fix is ready.
  3. Fix. Address the root cause, not just the immediate symptom, and add a regression check where practical so the same issue can't silently reappear.
  4. Recover. Confirm the fix is deployed and verify the exposure is fully closed.
  5. Review. Document what happened, why, and what changes as a result, the same way we already do for every security issue found in day-to-day review.

Client notification

For a Critical or High severity incident that affects a client's data, we will notify that client within 72 hours of confirming the incident, with what we know at the time and how we're responding. We'll follow up as our understanding develops.

Contact

To report a suspected security issue, email security@organiz.org. You don't need to go through a bug bounty program. We accept and respond to every good-faith report.

See also our Privacy Policy and Data Retention Policy.

On this page