Security incident process
Last updated: 2 September 2026
This is an internal operating process for suspected security or personal-data incidents. It does not by itself create a legal notification duty. Whether the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 require notice to individuals or the Data Protection Board — and from which date — is LEGAL REVIEW REQUIRED.
Steps we take
- Detect: unusual admin access, corrupted uploads, unexpected data exposure, or a credible report.
- Contain: rotate secrets, disable a compromised account, take a feature offline if needed. Do not destroy evidence.
- Investigate and preserve: keep logs, note systems touched, avoid overwriting backups that may be needed.
- Assess: whose personal data may be affected (accounts, listings, student records, payments identifiers).
- Notify: inform affected users in plain language when we reasonably believe it is necessary, and take legal advice before any Board or other authority notice.
- Recover and document: restore service, record what happened, and improve the control that failed.
How to report
- Email info@shardaitservices.com with “security” in the subject. Do not attach password lists or live card numbers.
