Incident Response Policy
Last updated: August 11, 2026
This policy describes how Ruligent detects, classifies, and communicates about operational and security incidents affecting the service or customer data.
1. Severity levels
- SEV-1 — Critical: confirmed breach of customer data, complete service outage, or a defect causing the guard to allow actions a policy should have blocked.
- SEV-2 — Major: partial outage or degradation of the guard endpoint, approvals, webhooks, or dashboard; suspected but unconfirmed security issue.
- SEV-3 — Minor: degraded non-critical functionality with a workaround; no data exposure and no impact on policy enforcement.
Because Ruligent SDKs fail closed by default, a full outage of the guard endpoint blocks guarded agent actions rather than letting them through; severity classification accounts for this containment property.
2. Detection
Incidents are detected through health-check monitoring of the API, error reporting (Sentry), platform log review, and reports from customers or security researchers to www.ruligent.com/contact.
3. Notification commitments
- Security incidents affecting your data: notice without undue delay, and no later than 72 hours after confirmation, to the organization admin email on file — including what happened, the data involved, and the actions we are taking. This aligns with the breach-notification obligations in the DPA.
- SEV-1/SEV-2 availability incidents: status updates to affected customers by email until resolved.
- SEV-3: noted in the changelog or release notes where relevant.
4. Response process
- Triage and classify the report against the severity levels above.
- Contain — including, where warranted, use of the platform kill switch, key revocation, or taking the affected component offline.
- Remediate the root cause and verify the fix in production.
- Notify per the commitments above.
- Review — a blameless post-incident review within 10 business days for SEV-1 and SEV-2 incidents, covering root cause, timeline, and prevention. A summary is available to affected customers on request.
5. Reporting an incident or vulnerability
Report suspected incidents or security vulnerabilities to www.ruligent.com/contact. See the Security Overview for our responsible disclosure practice. We do not pursue legal action against good-faith research.
Contact
Incident response contact: www.ruligent.com/contact (founder on-call).