VentaHR
Incident Response

Security Incident Response Process

Our documented approach to detecting, responding to, and recovering from security incidents

1. Detection

Automated monitoring systems, security alerts, and customer reports trigger incident detection.

  • 24/7 automated monitoring and alerting
  • Security event correlation and analysis
  • Customer-reported security concerns triaged immediately
  • Severity classification based on impact and scope
2. Triage & Assessment

Security team assesses incident severity, scope, and potential impact.

  • Incident severity classification (P1-Critical to P4-Low)
  • Impact assessment: data, systems, customers affected
  • Initial containment measures activated
  • Stakeholder notification initiated per severity
3. Containment

Immediate actions to limit incident spread and prevent further damage.

  • Isolate affected systems or accounts
  • Revoke compromised credentials
  • Block malicious traffic or activities
  • Preserve evidence for investigation
4. Eradication

Remove threat from environment and address root cause.

  • Identify and remove malicious artifacts
  • Patch vulnerabilities or misconfigurations
  • Update security controls
  • Verify threat elimination
5. Recovery

Restore systems and services to normal operation.

  • Restore from clean backups if necessary
  • Verify system integrity before restoration
  • Gradual service restoration with monitoring
  • Enhanced monitoring for recurrence
6. Post-Incident Review

Document lessons learned and implement improvements.

  • Incident timeline and response documentation
  • Root cause analysis
  • Identify process and control improvements
  • Update runbooks and procedures
Customer Notification

When are customers notified?

Customers are notified of security incidents that affect their data or service availability as contractually required and in compliance with applicable breach notification laws. Notification timing depends on incident severity and regulatory requirements.

What information is provided?

Notifications include: incident nature and scope, data potentially affected, containment and remediation measures taken, customer action items (if any), and contact information for questions.

Notification channels

Depending on severity: email to registered contacts, in-app notifications, status page updates, and direct outreach to affected accounts. Enterprise customers may have dedicated notification channels per agreement.

Uptime & Availability Commitment

Service Level Objectives

Target availability and uptime commitments are documented in service level agreements (SLAs). Historical uptime data is available to customers through status pages and account dashboards.

Incident Communication

Service disruptions and degradations are communicated through status pages with real-time updates. Customers can subscribe to status notifications via email or SMS.

Planned Maintenance

Planned maintenance is scheduled during low-usage periods with advance notice to customers. Most updates are deployed with zero downtime using rolling deployment strategies.

Report a Security Issue

If you discover a security vulnerability or have security concerns, please contact our security team

Responsible disclosure appreciated. Details provided confidentially to authorized personnel only.