A
AYONIX
ZOOMER

Incident Management and Response Policy

Version 1.0 · Effective 25 September 2026 · Owner: Ayonix engineering · Reviewed annually

1. Scope

Any event that compromises, or credibly threatens, the confidentiality, integrity or availability of Ayonix Zoomer or the data it holds. Because the service processes biometric data, any suspected exposure of face templates or evidence images is treated as Severity 1 from the moment it is suspected, not from the moment it is confirmed.

2. Severity

LevelDefinitionAcknowledgeCustomer notice
S1 — CriticalConfirmed or suspected exposure of biometric data, evidence images or credentials; cross-tenant data access; full service outage.1 hourWithin 24 hours of confirmation
S2 — HighExposure of non-biometric personal data; authentication or authorisation bypass; actively exploited vulnerability.4 hoursWithin 72 hours
S3 — MediumDegraded service; a vulnerability with no evidence of exploitation.1 business dayWith the fix
S4 — LowMinor issue with no data impact.3 business daysRelease notes

3. Response process

  1. Detect and report. Sources: automated alerts, the audit log, customer reports, and security@ayonix.com. Anyone may raise an incident; nobody needs permission to do so.
  2. Triage. An incident lead is named and assigns a severity. The lead owns the incident until it is closed.
  3. Contain. Revoke credentials, disable the affected path, or roll back. Preserve evidence before changing anything — logs, database state, deployment version.
  4. Eradicate and recover. Fix the cause, verify through the normal pipeline, deploy, and confirm in production.
  5. Notify. See below.
  6. Review. A blameless post-incident review within 5 business days, producing dated, owned corrective actions. Reviews examine the system that permitted the failure, not the person who tripped it.

4. Notification

5. Roles

RoleResponsibility
Incident leadOwns triage, containment and closure. Single decision-maker during the incident.
EngineeringInvestigation, fix, verification.
Privacy contactRegulatory assessment and notification wording.
Customer contactCommunicates with affected customers.

Ayonix is a small team; one person may hold several roles, but the incident lead is always named explicitly.

6. Evidence and records

Every incident is recorded: timeline, severity, systems and data involved, actions taken, who was notified and when, and the corrective actions. Records are retained for at least two years.

7. Testing

The process is exercised at least annually as a tabletop walkthrough of a realistic scenario — most usefully, suspected exposure of biometric templates — and the policy is updated with what the exercise finds.

8. Contact

Security incidents: security@ayonix.com · Privacy: privacy@ayonix.com · Support: support@ayonix.com