Incident response and breach notification

How Depozza detects, classifies, contains and communicates security incidents — including the 72-hour regulator deadline.

All compliance documents
Version
1.0 · Effective 2026-08-11
Owner
security@depozza.eu
Review cycle
Annual
Mapped controls
SOC 2 CC7 · ISO 27001 A.5.24–A.5.28 · GDPR art. 33–34

Detection

  • Application and server errors are captured centrally and reviewed.
  • Automated security scans run against the database configuration and dependencies.
  • Anyone — user, host or researcher — can report a suspected issue to security@depozza.eu.

Severity levels

  • P1 — confirmed exposure of personal data, payment data or account takeover. Response starts immediately.
  • P2 — exploitable vulnerability with no evidence of exploitation. Response within 1 business day.
  • P3 — low-impact issue or hardening gap. Scheduled into normal work.

Response steps

  • Contain: revoke the affected credentials or access path first.
  • Assess: determine which data and which users are affected, using the audit log.
  • Remediate: ship the fix and verify it against the original report.
  • Record: document timeline, root cause and follow-up actions.

Notification

If a personal-data breach is likely to result in a risk to individuals, Depozza notifies the competent supervisory authority (CNIL) within 72 hours of becoming aware of it, and informs affected users without undue delay when the risk is high. Notifications describe what happened, what data was involved and what users should do.

After the incident

Every P1 and P2 incident gets a written post-incident review with concrete preventive actions and an owner. Reviews are kept as evidence for audits.

Questions about this document

security@depozza.eu

This document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.