Incident Response Plan
Written before the incident happens, because on the day there is no time to decide who does what.
Version 1.0 — effective September 1, 2026.
1. What counts as an incident, and who decides
Unauthorized access, data loss or leakage, an outage with suspicion of malicious cause, a compromised credential. Any team member who notices one of these signs reports it immediately to the responsible contact (administrativo@parametrica.com.br). Classification belongs to that contact — and when in doubt, it is treated as an incident.
2. How it is detected
The systems log authentication attempts with origin and refusal reason, rate-limit the public routes, and continuously monitor the automated routines — including e-mail delivery failures, which have already surfaced a real problem before any complaint arrived. Human reports — from the team or from customers — come in through the support channel, with a number and a queue.
3. The first hour
Before touching anything, record: what happened, when it was noticed, which data sets were reached, how many people, and whether data left the environment. Without that snapshot, containment destroys the evidence.
4. Containment
- Immediate revocation of compromised sessions — per user or in bulk.
- Rotation of every credential reached, including infrastructure credentials.
- If needed, taking the service offline: a controlled outage is better than an ongoing leak.
5. Communication
- Customers whose data we process: the customer is the controller — Paramétrica informs them immediately, with what it knows; communicating to their data subjects is their decision.
- Data subjects and the Brazilian DPA (ANPD), when Paramétrica is the controller: without undue delay whenever there is relevant risk — what happened, which data, which risks, what has been done and what the data subject can do, as declared in the Privacy Policy.
6. Record and lesson
Every incident — externally communicated or not — is recorded, along with what was done. If the response revealed a missing or broken control, the fix becomes planned work, and the policies are updated with it.
Version 1.0 — September 1, 2026.