Incident Response
How AfriScore detects, responds to, and communicates security incidents.
AfriScore maintains a documented incident response process for security events affecting our systems, our subprocessors, or the data of the institutions we serve.
This page describes the process, the severity classifications, the timelines we commit to, and the communication expectations for institutional partners.
This page documents intent and process, not infrastructure. AfriScore is an early-stage company. Detection tooling, on-call rotation, and formal escalation paths are being built alongside the first paying CEMAC contract. The procedural commitments below are what we hold ourselves to in the meantime.
What counts as an incident
An incident is any event that materially threatens the confidentiality, integrity, or availability of systems or data handled by AfriScore. This includes, but is not limited to:
- Unauthorized access to production systems
- Unauthorized access to, or disclosure of, borrower data
- Loss or corruption of data
- Availability failures affecting institutional partners
- Security vulnerabilities in AfriScore systems that are being actively exploited
- Security incidents at a subprocessor that materially affect AfriScore
Routine operational events (scheduled maintenance, minor bugs, performance degradation without security impact) are not incidents and are handled through normal operational channels.
Severity classifications
Every incident is classified by severity. The classification determines the response timeline.
| Severity | Definition | Response target |
|---|---|---|
| SEV-1 | Confirmed breach, active exploitation, or loss of borrower data | Acknowledge within 1 hour, mitigation within 24 hours |
| SEV-2 | Suspected breach, active attack without confirmed data exposure, or partial service outage | Acknowledge within 4 hours, mitigation within 72 hours |
| SEV-3 | Degraded service, non-exploited vulnerability, or single-tenant impact | Acknowledge within 24 hours |
| SEV-4 | Low-impact issue, informational, or non-urgent | Handled during normal business hours |
Response phases
1. Detection
Incidents may be detected through:
- Automated alerting on production systems
- Manual review of logs by the founder (and, when onboarded, the COO)
- Reports from institutional partners
- Reports from security researchers via Vulnerability Disclosure
- Notification from a subprocessor
2. Triage
Once an incident is detected, it is assessed against the severity table above. The founder (and, when onboarded, the COO) determines the classification and initiates the appropriate response.
3. Containment
The immediate priority is to stop the incident from spreading or causing further damage. This may include:
- Revoking compromised credentials
- Isolating affected systems
- Disabling affected endpoints
- Coordinating with a subprocessor if the incident originates there
4. Investigation
Once containment is achieved, the scope of the incident is determined:
- What systems were affected
- What data was accessed, disclosed, or lost
- How the incident occurred
- What the root cause was
5. Remediation
The root cause is addressed. This may involve:
- Patching a vulnerability
- Rotating secrets
- Adding monitoring or alerting
- Changing a process or architecture
6. Communication
Institutional partners are notified per the timelines below.
7. Post-incident review
Within 7 days of resolution, a written post-incident review is produced. This documents the incident, the response, and the changes made to prevent recurrence. It is shared with affected institutional partners on request.
Communication commitments
AfriScore commits to the following notification timelines for institutional partners.
For SEV-1 incidents affecting borrower data
- Initial notification: Within 72 hours of confirmation
- Interim updates: Every 24 hours until the incident is resolved
- Post-incident report: Within 7 days of resolution
For SEV-2 incidents affecting availability
- Initial notification: Within 24 hours of confirmation
- Post-incident report: Within 7 days of resolution
For SEV-3 and SEV-4 incidents
- Reported in the next scheduled partner update, unless the institution requests otherwise
The 72-hour breach notification window is the standard commitment in GDPR-inspired data protection frameworks and is aligned with the requirements of most national data protection authorities in the regions where AfriScore operates.
What institutions can expect
If you are an institutional partner and an incident affects your data or your access to AfriScore services, you will receive:
- A clear description of what happened, in plain language
- The scope of the impact — what data, what systems, what users
- The containment and remediation actions taken
- A contact person at AfriScore for follow-up questions
- A written post-incident review once the incident is resolved
You will not receive speculation. If the scope is unclear, we will say so, and we will update you as the picture becomes clearer.
Coordination with regulators
Where required by national data protection law or by the institution's regulatory obligations, AfriScore will cooperate with the institution's notification to its regulator. We will provide the institution with the information it needs to make its own notification within its own regulatory deadlines.
Contact
To report a suspected incident, or to ask questions about incident response, contact security@afriscore.africa.
For institutional partners with a signed agreement, an emergency contact line will be provided during onboarding.