
Of Alarum, Containment & the Honest Telling
Incident Response & Breach Notification
Effective: August 7, 2026 · Version 1.0
This policy states what Strength & Solidarity LLC (“the LLC”) does when something goes wrong with BellusTowne’s security or the data entrusted to it. It is written to be read by Citizens, researchers, and regulators alike, and it binds us whether or not the law in a given place would require as much.
1. Scope
This policy covers any event that compromises, or credibly threatens to compromise, the confidentiality, integrity, or availability of BellusTowne systems or Citizen data. That includes unauthorised access, credential compromise, malicious insider activity, third-party processor breaches, ransomware, and the accidental disclosure of data by us.
2. Severity ladder
| Tier | What it means | Acknowledge | Contain | Notify |
|---|---|---|---|---|
| P0 — Breach | Confirmed unauthorised access to, or exfiltration of, Citizen personal data, credentials, or payment identifiers. | 1 hour | 4 hours | Affected Citizens within 72 hours of confirmation |
| P1 — Critical | An exploitable flaw that could yield P0 if used, or a total outage of authentication, payments, or the age gate. | 4 hours | 24 hours | Public status notice; individual notice only if data was reached |
| P2 — Serious | A functional or security defect that degrades a load-bearing rite — checkout, intake, moderation — without exposing data. | 1 business day | 5 business days | Noted in the Towne Crier if Citizens were materially affected |
| P3 — Minor | Cosmetic, informational, or low-impact defects with no security or data consequence. | 5 business days | Next ordinary release | None required |
Timers begin when the LLC first has a credible report, not when the incident began. When severity is uncertain we assume the higher tier until proven otherwise.
3. The rite of response
- Detect & triage. The report is logged with a timestamp, a severity tier, and an Incident Commander. Every subsequent action is recorded against that log.
- Contain. Stop the bleeding before understanding it: revoke credentials, disable the affected route or table, throw the relevant circuit breaker, or take the surface offline. Availability is sacrificed to confidentiality without hesitation.
- Assess. Determine what data was reachable, what was actually reached, how many Citizens are affected, and whether the exposure is ongoing. Preserve logs and evidence before remediating.
- Notify. Per section 4. We do not delay notice to finish the investigation; we send what we know and follow with what we learn.
- Remediate. Close the flaw, rotate every credential in the blast radius, and add a regression check so the same door cannot open twice.
- Post-mortem. Within 30 days of closure we write a blameless account: timeline, root cause, what we changed. For any P0 or P1 the summary is published.
4. Notification thresholds
- Affected Citizens — without undue delay and no later than 72 hours after we confirm a breach of personal data, by email to the address of record and by notice within the Towne. We apply this 72-hour standard worldwide as a matter of policy, not only where law compels it.
- Supervisory authorities — where a Citizen is subject to a regime requiring it (for example the UK/EU GDPR), within 72 hours of awareness.
- State attorneys general and consumer agencies — on the timelines the relevant United States state breach statutes require, and in every case without undue delay.
- Payment processors — immediately, where payment identifiers are implicated. We do not store full card numbers; card data is handled by our processor.
- The public — a notice on this site for any P0, and for any P1 that caused a material outage.
We will not use a law-enforcement request to indefinitely suppress notice. If a lawful request delays disclosure, we will say so once the hold lifts and state how long it ran.
5. What a notice will contain
- What happened, in plain language, and when we learned of it.
- Which categories of your data were involved — and which were not.
- What we have done to contain and remediate it.
- What you should do (change a password, enrol a second seal, watch a statement).
- A named contact and a date for the next update.
A standing notice template is held ready so that no wording is invented under pressure.
6. Roles
- Incident Commander — the Founder of BellusTowne, on behalf of the LLC. Holds sole authority to declare severity, take surfaces offline, and approve notices.
- Technical Lead — the engineering steward of record, responsible for containment, forensics, and remediation.
- Communications — the Towne Crier, responsible for Citizen-facing notice and the published post-mortem.
These are roles, not headcount. In a small house one person may hold more than one; the duties do not thereby lapse.
7. Reporting an incident to us
Write to security@bellustowne.com. Researchers should follow the responsible-disclosure policy, which carries a safe-harbour pledge. Citizens who suspect their own account has been compromised should write to the same address and change their password immediately.
8. Review
This policy is reviewed at least annually and after every P0 or P1 incident. Material changes are posted here with a new version number and date.