Purpose
This document is a public overview of how Velaris Management Group LLC (“Xive”) prepares for, detects, contains, recovers from, and learns from security incidents that affect the Services or data we process on behalf of users and customers. It is not a full internal playbook, chain-of-custody manual, or forensic standard operating procedure.
- Preventive and baseline security controls are summarized in our Data Storage & Security Overview.
- What personal data we hold, and how long we keep logs or incident artifacts, is governed by our Privacy Policy and Data Retention Policy.
- Operational detail (on-call rosters, exact tooling, and evidence storage) is kept confidential to protect the effectiveness of our defenses.
Governance and authority
When a credible incident is declared, named responders coordinate technical work while legal and leadership align on regulatory, contractual, and communications obligations.
- Designated responders may order containment steps such as credential rotation, session invalidation, IP or account blocks, feature toggles, or traffic shaping to stop active abuse.
- Legal counsel is involved early when personal data may have been exposed, when law enforcement reaches out, or when breach-notification statutes may apply.
- Executive stakeholders approve external statements, major customer outreach, and trade-offs between transparency and an ongoing criminal or national-security investigation.
Detection
We treat “incident” broadly: anything that suggests unauthorized access, loss of confidentiality or integrity, denial of service at scale, or active exploitation of a vulnerability in our environment.
- Automated alerts from infrastructure, application, and security tooling; anomaly detection where deployed.
- Notifications from cloud providers, payment partners, or other vendors when their systems affect ours.
- Internal reports from employees or contractors who notice suspicious behavior.
- External reports, including coordinated vulnerability disclosure and good-faith tips from researchers or users.
Containment, eradication, and recovery
Once we reasonably believe an incident is real—not a false alarm—we prioritize stopping harm, preserving evidence, and returning critical services to a known-good state.
- Containment: isolate affected hosts or services, revoke compromised credentials, block malicious traffic, or temporarily disable risky features while we investigate.
- Eradication: remove malware, close exploited misconfigurations, deploy patches, and validate that attacker access paths are closed.
- Recovery: restore from backups or redeploy clean artifacts, re-enable services gradually, and monitor for recurrence.
- Forensic artifacts are collected and handled under legal guidance so they remain admissible and privacy-respecting.
We aim to limit downtime and user-visible disruption, but safety and data integrity take precedence over convenience when those goals conflict.
Notification and cooperation
When applicable law or contracts require us to notify regulators, affected individuals, or enterprise customers about a personal-data breach, we do so without undue delay once we have enough facts to make a meaningful statement.
- Law enforcement may ask us to delay part of a public notice while an investigation is active; we comply only where the law clearly permits and we still meet any non-waivable duties to users.
- Enterprise or partner contracts may specify shorter notice windows, dedicated contacts, or joint communication plans—we honor those where they are valid and operational.
- We do not promise to notify every user of every low-severity operational glitch; we focus notifications on incidents that materially affect confidentiality, integrity, or availability of personal or sensitive business data.
Post-incident review
After significant incidents we run structured, blameless reviews so individuals are not punished for reporting problems while the organization still fixes root causes.
- Outputs may include updated runbooks, additional monitoring, training, architecture changes, or vendor escalations.
- Action items are tracked to completion when staffing and budget allow; we accept that some backlog may exist after very large events.
Contact
To report a security vulnerability or suspected breach, use the security contact published in the Service. If none is listed, email [email protected] with a concise description and, when safe, steps to reproduce—do not include live user passwords.