Employee Center Security Incident and Breach Response Policy
No Raw Database Data Claim
For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.
This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.
Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policies Hub: /legal/policies
Policy URL: /legal/policies/security-incident-breach-response-policy
1. Purpose
This policy explains how EC may respond to suspected security incidents, breaches, credential compromise, unauthorized access, or data-risk events.
2. Incident Examples
Incidents may include unauthorized access, suspicious logins, credential leaks, malware, phishing, data exports, API misuse, automation abuse, database access, backup deletion, attempted lockout, attempted seizure, or suspicious certificate access.
3. Response Actions
EC may suspend accounts, revoke sessions, rotate credentials, disable APIs, disable integrations, restrict exports, preserve logs, preserve backups, create forensic copies, restore systems, notify appropriate parties where required, and seek legal relief.
4. Evidence Preservation
Incident records may be preserved for security, evidence, legal defense, enforcement, and evidence preservation and authorized transition support.
5. Disclosure Control
Technical details may be delayed or limited where disclosure could increase risk, interfere with investigation, reveal credentials, or harm EC security.
Changes to This Policy
Quintin N. Mahan may update this policy by publishing a new active version in EC.
The current active version will be displayed through the Legal hub.
Older versions may remain stored in Postgres for audit, evidence, and historical review.
Contact / Owner
Employee Center is owned by Quintin N. Mahan.
Legal and policy documents are available from:
/legal
The current Terms and Conditions are available from:
/legal/terms-and-conditions
End of Employee Center Security Incident and Breach Response Policy.