Security incident response
The public version of the Banalytics process for receiving, assessing, containing and communicating security and privacy incidents.
Incidents handled by Banalytics
This process covers the public website, hosted Portal, company-controlled accounts and release channels, and vulnerabilities in software distributed by Banalytics. Incidents confined to customer-controlled Agent infrastructure are handled by the owner unless a signed support agreement assigns a role to Banalytics.
Response stages
- Receive and record: create a restricted Jira record with the source, time, affected asset and known facts.
- Triage: determine whether the report is credible, what Banalytics-controlled systems or releases are affected and whether personal data may be involved.
- Contain: limit access, revoke credentials, disable an affected function or pause a release where proportionate.
- Investigate: preserve relevant evidence, identify the cause, affected versions, data and users, and record decisions.
- Remediate and recover: correct the issue, test the corrective action and restore the affected service or release path.
- Communicate: notify affected customers, authorities or other parties when law or contract requires it.
- Review: record lessons learned and update product, process or documentation.
Legal and contractual communication
Banalytics does not promise that every security event will be publicly announced. Notification depends on the affected system, confirmed impact, applicable law and contract.
- Where Banalytics is a GDPR controller, it assesses whether a personal-data breach must be notified to the supervisory authority and affected individuals.
- Where Banalytics is a processor under a signed DPA, it notifies the customer without undue delay after confirming a breach affecting customer-processor data.
- From the applicable CRA reporting date, Banalytics will assess actively exploited vulnerabilities and severe product-security incidents against the statutory reporting requirements.
- A pilot or Enterprise contract may specify additional contacts and communication commitments.
Report an incident
Contact info@banalytics.live with the subject Security incident. Do not include credentials, personal data or customer recordings until an appropriate transfer channel is agreed.
Banalytics currently has no fixed Community Edition incident-response SLA. Contract-specific contacts and response commitments may be agreed for pilots and Enterprise deployments.
Last updated: 23 July 2026.