Version 1.0 · Effective October 4, 2026 · Reviewed every year and after every incident
Incident response plan
What Blue Ridge Federal does when the security of the client portal, the processing service or client data may be at risk.
Scope and roles
Covers: blue-ridge-federal.com, the client dashboard and API, the database and encrypted file storage, the processing service and its machine, and every account and key that operates them.
Incident lead: Joseph Benson, Founder (jbenson@blue-ridge-federal.com, (917) 412-1478), who decides severity, containment and notification. Report anything suspicious to the same address; reports are acknowledged within two business days, and suspected incidents at once.
Severity: High if client data may have been read, changed or deleted by anyone not authorized, or a key or credential may be exposed. Medium if a control failed without evidence of data exposure. Low for an attempt that every control stopped.
The six steps
1. Detect and record
Sources: client and researcher reports, the processing service’s alerts, the append-only access and job logs, hosting and identity-provider alerts. Open an incident record with the time, the reporter and the first facts, and keep it updated throughout.
2. Contain within the first hour for High
- Stop the processing service and rotate its token.
- Revoke affected API keys and sign out affected sessions; suspend an affected organization if needed.
- Revoke every support-access grant.
- Rotate the file-encryption service key (organization keys are re-wrapped under the new key without re-uploading data) and any exposed provider credential.
- Turn off model assistance and outside catalog lookups for the affected organizations.
3. Preserve and assess
Preserve the access and job logs (they cannot be edited or deleted), hosting and identity-provider logs, and the processing machine’s state before changing it. Establish what happened, when, which organizations and which data, from evidence rather than assumption.
4. Notify
Notify every affected organization’s owners without undue delay and no later than 72 hours after confirming that its data was affected: what happened, what data was involved, what we have done, what we recommend and who to contact. Update them as facts change. Notify authorities when the law or a contract requires it, within the time it requires.
5. Recover
Fix the cause, verify the fix with tests, restore service, and confirm with each affected organization that its access and data controls are as it expects.
6. Review
Within ten business days, write down the cause, the timeline, what worked and what did not, and the changes made to prevent a repeat. Affected organizations receive the summary on request.
Kept ready
Contacts for the hosting, identity, payment and catalog providers; the procedure to rotate each key and token; and a yearly tabletop exercise of this plan. Questions about this plan: jbenson@blue-ridge-federal.com. See also Security & Trust.
