Incident Response Plan
Updated: February 15, 2026
Keelio Software, LLC ("Company," "we," "us," or "our") takes the security of our customers' data seriously. This Incident Response Plan describes, at a public level, how we prepare for, detect, respond to, and communicate about security or data incidents affecting our services. It is intended to give customers and partners visibility into our practices; it does not disclose internal technical procedures, credentials, or other information that could undermine our security posture.
1. PURPOSE & SCOPE
This plan applies to any suspected or confirmed incident involving the confidentiality, integrity, or availability of Keelio Software systems, services, or the data we process, including but not limited to unauthorized access, data breaches, malware, denial-of-service events, and lost or stolen devices or credentials.
2. INCIDENT RESPONSE TEAM
Keelio Software designates internal personnel responsible for triaging, investigating, and coordinating the response to reported incidents. Depending on the nature and severity of an incident, our response team engages relevant technical staff, company leadership, our hosting provider, and outside counsel or forensic specialists as needed.
3. DATA PROTECTION & BACKUPS
We only store the customer data described in our Privacy Policy (such as names, contact details, and billing addresses). We do not store payment card data on our own servers; all payment processing and storage of payment instrument data is outsourced to Stripe, a PCI DSS Level 1 certified payment processor, so cardholder data is never retained within Keelio Software systems.
All data is backed up daily. In the event of a confirmed data or security breach, we will force a reset of all potentially affected passwords and require re-authentication as part of our containment and recovery process.
4. SEVERITY CLASSIFICATION
Reported incidents are triaged and assigned a severity level based on their scope and potential impact, which determines the urgency of our response:
- Critical. Confirmed unauthorized access to, or exposure of, customer data, or a complete loss of service availability.
- High. Suspected unauthorized access or a significant service disruption affecting multiple customers.
- Medium. Isolated or contained issues with limited customer impact.
- Low. Minor issues with no meaningful risk to customer data or service availability.
5. RESPONSE PROCESS
Our response to a confirmed or suspected incident generally follows these phases:
- Detect. Incidents may be identified through automated monitoring and alerting, internal review, or reports from customers, partners, or security researchers.
- Contain. We take immediate action to limit the scope of the incident, which may include revoking credentials, isolating affected systems, or disabling impacted functionality.
- Investigate. We assess the root cause, scope, and impact of the incident, including which systems and data may have been affected.
- Eradicate & Recover. We remediate the underlying cause and restore affected systems and services to normal operation.
- Communicate. We notify affected customers and, where required, regulators or other authorities, in accordance with applicable law and our contractual obligations. See Section 6 below.
6. CUSTOMER & REGULATORY NOTIFICATION
If we determine that an incident has resulted in a confirmed data or security breach affecting your data, we will notify affected customers without undue delay, using the contact information on file for your account. Notifications will describe, to the extent known, the nature of the incident, the data or systems involved, and the steps we are taking in response. Where applicable law requires notice to regulators or data protection authorities, we will make such notifications within the required timeframes.
7. POST-INCIDENT REVIEW
Following resolution of a significant incident, we conduct an internal review to identify the root cause and any gaps in our controls, and to implement corrective actions intended to reduce the likelihood or impact of similar incidents in the future.
8. REPORTING A SECURITY CONCERN
If you believe you have discovered a security vulnerability, or you suspect a data or security incident affecting Keelio Software, please contact us immediately at support@keelio.com so that we can begin our response process. Please include as much detail as possible, such as the systems or data involved and how the issue was discovered.
9. PLAN REVIEW & UPDATES
We periodically review and update this Incident Response Plan to reflect changes in our systems, services, and applicable legal or regulatory requirements. This page will be updated to reflect the date of the most recent review.