OpsRabbit Trust Center

Incident and Breach Notification

Public incident response, customer coordination and breach notification practices for OpsRabbit.

PublicVersion 1.0September 2026

Overview

This page explains how the OpsRabbit provider prepares for, identifies, contains, investigates, communicates and learns from security, privacy and AI incidents involving OpsRabbit or provider-controlled customer data. It is a public summary; the applicable agreement, Data Processing Addendum and law govern specific notification duties and timelines.

Scope

Covered events include unauthorized access or disclosure, credential compromise, data leakage, integrity loss, service disruption, harmful or unauthorized AI behavior, prompt injection, misuse of models or tools, unauthorized production actions, cross-customer exposure and material failures of product safeguards.

Operational issues that do not create a security, privacy or material AI risk may follow normal support processes, but they are escalated when evidence indicates broader impact.

Response principles

  • Protect people, customer operations and evidence before restoring ordinary service.
  • Work within the customer-hosted shared-responsibility model.
  • Communicate verified facts, known uncertainty and the next expected update.
  • Contain access using the least destructive effective action without unnecessarily destroying logs or evidence.
  • Assess contractual and legal notification requirements without waiting for a complete root-cause determination.

Roles and coordination

A designated incident lead owns severity, decisions, coordination, the incident timeline and closure. Technical and security responders investigate, preserve evidence, contain the event and restore affected product capabilities. Privacy or legal reviewers assess personal-data and notification obligations. AI specialists assess prompt, retrieval, model, tool and evaluation failures. The customer incident lead coordinates customer-controlled infrastructure, identities, business impact and customer decisions.

Roles may be combined based on incident scope, but decision authority, actions and external communications are recorded.

Severity and escalation

Events are classified and re-evaluated using confidentiality, integrity, availability, safety, customer impact, affected privilege, persistence, active exploitation, regulatory exposure and operational consequence.

LevelPublic description
CriticalConfirmed or likely material exposure, unauthorized production action, active compromise, major service disruption, safety impact or broad customer impact.
HighContained exposure, significant control failure, repeated harmful output or material service degradation.
MediumLimited impact, suspicious activity, isolated incorrect output or a vulnerability without known active exploitation.
LowMinor event, policy question or quality issue without material security, privacy or operational impact.

Severity may increase or decrease as evidence develops. Contractual or legal requirements may require escalation regardless of the initial classification.

Activation and first actions

ul

Response lifecycle

  1. Detect and report. Accept signals from monitoring, users, customers, model evaluations, security testing and providers. Preserve the original signal and reporter context.
  2. Triage. Validate the event, identify affected customers, environments, identities, data, models, tools and time windows, and determine which technical, customer, privacy or legal roles must participate.
  3. Contain. Revoke or rotate credentials, disable tools or connectors, block egress, suspend workflows, isolate affected components or move to read-only operation as appropriate.
  4. Investigate and eradicate. Preserve logs and versions, reconstruct the sequence, remove malicious content or access, correct configuration and remediate the root cause.
  5. Recover. Restore from a trusted state, validate permissions and data integrity, run relevant regression or adversarial tests and monitor for recurrence.
  6. Communicate. Provide verified scope, impact, containment, required actions and update expectations through the agreed channel.
  7. Close and learn. Record root cause, control failures, corrective actions, owners and follow-up evidence.

Customer-hosted response

The OpsRabbit provider investigates product code, model orchestration, product safeguards and provider-controlled support access. The customer leads containment and recovery for customer-controlled cloud, network, identity, host, database and integration controls. Where a customer contracts directly with a cloud, identity, model or integration provider, the customer leads that provider relationship while the OpsRabbit provider supplies relevant product evidence and assistance.

For customer-issued credentials, the customer revokes or rotates the credential and investigates the source system; the OpsRabbit provider disables affected product use and supports the investigation.

AI incident scenarios

ScenarioPotential containmentInvestigation focus
Prompt injectionStop the affected workflow, disable the tool path or isolate the source.Source content, instruction boundary, tool calls, output and affected users.
Data leakageBlock output or egress, revoke access and preserve logs.Data types, recipients, model provider, storage, caches and copies.
Unauthorized actionStop automation, revoke tool permission and apply an approved rollback.Approval decision, actor, command, result, impact and permission path.
Materially wrong recommendationWarn users, suppress the affected capability and require manual review.Evidence retrieval, model or prompt version, expected result and downstream reliance.
Credential exposureRotate or revoke the credential and disable the connector.Where the secret appeared, access logs, model context, output and persistence.
Cross-customer exposureDisable the affected access path and treat it as a critical event.Tenant boundary, queries, storage, recipients and the exposure window.

Notification and communications

When notification is required, the OpsRabbit provider notifies the customer according to the applicable agreement and law and provides reasonable assistance. Communications use verified facts and identify known uncertainty rather than speculation.

Available updates may include the incident nature, affected systems or data, likely consequences, containment and remediation status, recommended customer actions, relevant indicators, the communication contact and when a further update is expected. Regulatory, affected-person and public notifications are coordinated by the party responsible under the applicable role, agreement and law.

Evidence and records

Responders preserve relevant timestamps, user and service identities, request identifiers, model and prompt versions, retrieved sources, tool calls, approvals, outputs, configuration and change history. Incident records are restricted to authorized responders and protected from unnecessary personal-data or secret exposure.

A single approved timeline and decision log records material facts, actions, decisions, evidence references, external notifications and approvals.

Recovery and improvement

Recovery begins from a trusted state and includes validation of access, configuration, data integrity, product behavior and monitoring. Closure records root cause, control gaps, corrective actions, accountable owners and completion evidence. Significant or repeated incidents may trigger updates to threat models, evaluations, safeguards, documentation and response procedures.

Readiness and reporting

Incident-response readiness is reviewed periodically and after material changes or significant incidents. Exercises should cover customer coordination, evidence preservation, notification decisions and relevant AI risks such as prompt injection or data leakage.

Suspected incidents involving OpsRabbit may be reported to info@OpsRabbit.io. Reports should avoid unnecessary customer data or credentials and should include the affected component, observed time, impact and safe supporting evidence.