1. Scope
Any event that compromises, or credibly threatens, the confidentiality, integrity or availability of Ayonix Zoomer or the data it holds. Because the service processes biometric data, any suspected exposure of face templates or evidence images is treated as Severity 1 from the moment it is suspected, not from the moment it is confirmed.
2. Severity
| Level | Definition | Acknowledge | Customer notice |
|---|---|---|---|
| S1 — Critical | Confirmed or suspected exposure of biometric data, evidence images or credentials; cross-tenant data access; full service outage. | 1 hour | Within 24 hours of confirmation |
| S2 — High | Exposure of non-biometric personal data; authentication or authorisation bypass; actively exploited vulnerability. | 4 hours | Within 72 hours |
| S3 — Medium | Degraded service; a vulnerability with no evidence of exploitation. | 1 business day | With the fix |
| S4 — Low | Minor issue with no data impact. | 3 business days | Release notes |
3. Response process
- Detect and report. Sources: automated alerts, the audit log, customer reports, and security@ayonix.com. Anyone may raise an incident; nobody needs permission to do so.
- Triage. An incident lead is named and assigns a severity. The lead owns the incident until it is closed.
- Contain. Revoke credentials, disable the affected path, or roll back. Preserve evidence before changing anything — logs, database state, deployment version.
- Eradicate and recover. Fix the cause, verify through the normal pipeline, deploy, and confirm in production.
- Notify. See below.
- Review. A blameless post-incident review within 5 business days, producing dated, owned corrective actions. Reviews examine the system that permitted the failure, not the person who tripped it.
4. Notification
- Customers (data controllers) are notified on the timeline above, with what happened, what data was involved, what we have done and what they should do. We notify on confirmation rather than waiting for a complete investigation.
- Regulators. Ayonix acts as a processor and supports the controller's obligations, including the GDPR's 72-hour deadline and reporting to Japan's Personal Information Protection Commission where the APPI requires it. Leakage of 個人識別符号 is expressly reportable.
- Affected individuals are notified by the controller; we provide the facts needed to do so.
- We will not quietly close an incident that affected a customer's data.
5. Roles
| Role | Responsibility |
|---|---|
| Incident lead | Owns triage, containment and closure. Single decision-maker during the incident. |
| Engineering | Investigation, fix, verification. |
| Privacy contact | Regulatory assessment and notification wording. |
| Customer contact | Communicates with affected customers. |
Ayonix is a small team; one person may hold several roles, but the incident lead is always named explicitly.
6. Evidence and records
Every incident is recorded: timeline, severity, systems and data involved, actions taken, who was notified and when, and the corrective actions. Records are retained for at least two years.
7. Testing
The process is exercised at least annually as a tabletop walkthrough of a realistic scenario — most usefully, suspected exposure of biometric templates — and the policy is updated with what the exercise finds.
8. Contact
Security incidents: security@ayonix.com · Privacy: privacy@ayonix.com · Support: support@ayonix.com