Tentunit Business — Security & Incident Response Policy
Version 1.0 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business
This page is informational. It explains, but does not override, the Data Processing Addendum and the Platform Terms of Service, which control.
1. Overview & Definitions
This page explains how Tentunit prepares for, detects, and responds to security events affecting Tentunit Business, and what you can expect from us if something goes wrong. The binding commitments — including breach-notification timelines and liability terms — live in the Data Processing Addendum and the Platform Terms of Service.
1.1 Purpose and Scope
This Security & Incident Response Policy describes Tentunit’s incident-response program for Tentunit Business, covering the systems Tentunit operates and the Customer Data and Tenant Data it processes. It does not cover systems you operate yourself (your devices, email accounts, or networks) or services you contract directly with third parties, although Section 6 describes how to report problems you observe anywhere in the ecosystem.
1.2 Key Definitions
- “Security Incident” means any event that actually or reasonably appears to compromise the confidentiality, integrity, or availability of Tentunit systems or the data they process — for example, unauthorized access attempts, malware, denial-of-service attacks, or significant misconfigurations. Not every Security Incident involves personal data.
- “Personal Data Breach” means the subset of Security Incidents involving accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (including Tenant Data), consistent with the definition in the Data Processing Addendum and applicable data protection law (including the GDPR and UK GDPR).
1.3 Why the Distinction Matters
The classification drives the response: all Security Incidents follow the lifecycle in Section 2, but only Personal Data Breaches trigger the customer-notification commitments described in Section 3.1 and the corresponding obligations in the Data Processing Addendum.
2. Incident Lifecycle
Tentunit follows a structured, repeatable process for every incident, from first alert to final lessons learned. This section walks through the stages.
2.1 Detection
Tentunit maintains monitoring of its production environment on a 24/7 basis, using automated alerting on infrastructure, application, and security telemetry, supplemented by reports from employees, customers, and security researchers. Suspicious signals are routed to the security team promptly for evaluation.
2.2 Triage and Severity Classification
Each potential incident is triaged to confirm whether it is genuine, determine its scope, and assign a severity level based on the sensitivity of affected data, the number of customers and tenants potentially impacted, and the effect on service availability. Severity classification determines escalation paths, response urgency, and who is engaged internally — including legal and privacy teams whenever personal data may be involved.
2.3 Containment
Once an incident is confirmed, the immediate priority is to stop it from spreading: isolating affected systems, revoking compromised credentials or sessions, blocking malicious traffic, and disabling exploited functionality where necessary. Containment decisions balance stopping the threat against preserving evidence (see Section 5.3).
2.4 Eradication
After containment, Tentunit removes the root cause — eliminating malware or unauthorized access paths, patching exploited vulnerabilities, correcting misconfigurations, and hardening the affected components against recurrence.
2.5 Recovery
Affected systems and data are restored to normal operation from trusted builds and backups, with heightened monitoring during the recovery period to confirm the threat has not persisted. Service-availability impacts during recovery are handled under the Platform Availability, Support & SLA.
2.6 Post-Incident Review
Every significant incident concludes with a post-incident review that documents the timeline, root cause, impact, and effectiveness of the response, and produces tracked corrective actions. Lessons learned feed back into controls, monitoring rules, and this program.
3. User Notification Rules
If an incident affects you or your tenants, you should hear it from us — clearly and quickly. This section explains when and how Tentunit notifies customers.
3.1 Personal Data Breaches
Where a Personal Data Breach affects Tenant Data or other Customer Data, Tentunit will notify affected business customers without undue delay and in any event within 72 hours of becoming aware of the breach, as committed in the Data Processing Addendum. Because you are typically the data controller for your Tenant Data, Tentunit’s notification is designed to enable you to meet your own obligations to regulators and affected individuals; notifying tenants and supervisory authorities is generally your responsibility as controller, and Tentunit will provide reasonable assistance as described in the Data Processing Addendum.
3.2 Service Incidents
For incidents affecting availability or performance without a Personal Data Breach (outages, degradations, disruptive maintenance events), Tentunit communicates through its status page and, for significant events, by email to account contacts. Uptime commitments and service credits are governed by the Platform Availability, Support & SLA.
3.3 What a Notification Contains
A breach notification will describe, to the extent known at the time: the nature of the incident; the categories and approximate volume of data and individuals affected; the likely consequences; the measures taken or proposed to address the breach and mitigate harm; and a contact point ([email protected]) for follow-up. Where full details are not yet available, Tentunit provides information in phases rather than delaying the initial notice.
3.4 Law-Enforcement Holds
In limited cases, law enforcement may lawfully require Tentunit to delay or restrict notification so as not to compromise an active investigation (“no tipping off”). In those cases, Tentunit will notify affected customers as soon as, and to the fullest extent, legally permitted.
4. Containment & Remediation
Beyond the immediate lifecycle, Tentunit applies a standard toolkit of containment and remediation measures scaled to the incident. This section summarizes the main ones.
4.1 Credential and Access Controls
Compromised or suspect credentials, API keys, tokens, and sessions are rotated or revoked promptly. Where warranted, Tentunit may force password resets or re-authentication for affected accounts and will tell you when it does so.
4.2 Isolation and Traffic Controls
Affected hosts, containers, or network segments are isolated from production, and malicious sources are blocked at the network edge, to limit lateral movement while the investigation proceeds.
4.3 Patching and Hardening
Exploited vulnerabilities are patched or mitigated with priority appropriate to their severity, and related components are reviewed for the same weakness. Fixes are validated before affected services return to normal operation.
4.4 Third-Party Forensics
For incidents that are complex, high-severity, or involve potential legal exposure, Tentunit engages independent digital-forensics and incident-response specialists to support the investigation, validate findings, and strengthen the evidentiary record.
5. Investigation & Resolution
Closing the ticket is not the end of the job. Tentunit investigates until the cause is understood, fixes are in place, and obligations to regulators and customers are met.
5.1 Root-Cause Analysis
Significant incidents receive a structured root-cause analysis that looks beyond the immediate trigger to contributing factors in architecture, process, and tooling, so that fixes address the underlying weakness rather than the symptom.
5.2 Corrective Actions
Corrective and preventive actions identified in the analysis are assigned owners and tracked to completion. Where an incident reveals a systemic issue, remediation may include changes to controls, vendor arrangements, or product design.
5.3 Evidence Preservation
Tentunit preserves logs, forensic images, and other relevant records associated with significant incidents in a manner that maintains their integrity, supporting regulatory inquiries, legal proceedings, and customer questions. Retention of these records is handled consistently with the Audit & Record Retention Policy.
5.4 Regulator Cooperation
Tentunit cooperates in good faith with supervisory authorities and other competent regulators in connection with Personal Data Breaches and other reportable incidents, and provides reasonable assistance to customers responding to regulator inquiries about incidents affecting their data, as described in the Data Processing Addendum.
6. Customer Responsibilities
Security is shared: Tentunit protects the platform, and you protect your accounts and tell us quickly when something looks wrong. This section covers your side.
6.1 Report Suspected Incidents
If you suspect a security incident affecting your Tentunit Business account or data — unauthorized logins, unexpected configuration changes, phishing that impersonates Tentunit, suspicious tenant-facing messages — report it promptly to [email protected] with as much detail as you can safely provide. Early reports materially improve response outcomes.
6.2 Keep Contacts Current
Breach and incident notifications go to the account and security contacts on file. Keep your administrative contact details current, and designate a security contact where your organization has one, so notices reach the right people without delay.
6.3 Account and MFA Hygiene
Use strong, unique passwords; enable multi-factor authentication for all Authorized Users; remove access promptly when staff leave or change roles; and follow the access-management practices described in the User Roles & Permissions Policy. Tentunit is not responsible for incidents caused by compromised customer credentials where the compromise results from your failure to maintain reasonable account security, as set out in the Platform Terms of Service.
6.4 Questions
Questions about this page may be directed to [email protected]. Data protection questions are handled at [email protected].