Finducation™

EZBudget™

Incident Response Policy

Defined process for detecting, triaging, resolving, and notifying on security incidents.

Document ID: EZB-IR-001
Version: 1.1
Effective Date: July 22, 2026
Last Review Date: July 22, 2026
Owner: Deseo Developers LLC — Sole Operator
Applies To: Security incidents affecting Finducation / EZBudget systems or data

1. Policy Statement

Deseo Developers LLC maintains a documented incident response process to detect, triage, contain, eradicate, recover from, and notify on security incidents affecting Finducation applications, including EZBudget and related integrations (authentication, Plaid, Stripe, hosting, and data stores).

2. Scope

  • Unauthorized access to accounts, APIs, databases, or cloud consoles
  • Suspected or confirmed data breach / exfiltration
  • Malware, ransomware, or credential compromise on maintainer endpoints with production access
  • Abuse of APIs, injection attempts with material impact, or denial-of-service affecting availability
  • Misconfiguration or secret exposure that creates material risk
  • Vendor/subprocessor incidents that may affect Finducation customer data

3. Roles and Contacts

Deseo Developers LLC is a sole-operator organization. The sole operator serves as Incident Lead, technical responder, and communications contact.

RoleResponsibility
Incident Lead / Technical Responder / Communications Sole operator — coordinates response, contains/remediates via Netlify / Supabase / GitHub, and handles customer, partner, and regulatory notifications

Primary contact: contact@deseodevelopers.com

Security reports should be sent privately to the contact above (not via public issue trackers).

4. Detection Sources

  • Application and function logs (structured logging; Netlify function logs)
  • Supabase Auth / database logs and anomaly indicators
  • GitHub / Netlify deploy and access events
  • Provider notices from Stripe, Plaid, Netlify, or Supabase
  • Customer reports and abuse reports
  • Maintainer reports of lost devices, phishing, or credential compromise

5. Severity Classification

SeverityDefinitionInitial Response Target
SEV-1 Critical Confirmed breach, active exploitation, or widespread customer data exposure Immediate (within hours)
SEV-2 High Likely compromise or significant vulnerability being exploited / imminent Same business day
SEV-3 Medium Suspicious activity or limited impact requiring investigation Within 2 business days
SEV-4 Low Minor anomalies, blocked attempts, or informational events As capacity allows; track for trends

6. Response Process

6.1 Identify & Triage

  • Log the incident (date/time, reporter, systems affected, initial severity).
  • Preserve relevant logs and evidence before destructive changes when feasible.
  • Assign Incident Lead and severity.

6.2 Contain

  • Revoke compromised sessions, API keys, and access tokens.
  • Disable or rotate secrets in Netlify / Supabase / third-party dashboards.
  • Block abusive traffic or temporarily disable affected endpoints if required.
  • For Plaid-related compromise, revoke affected Item access tokens and disconnect impacted links.

6.3 Eradicate & Recover

  • Remove root cause (patch, config fix, dependency update, credential rotation).
  • Restore from last known-good Netlify deploy if needed.
  • Verify authentication, Plaid, and billing-critical paths after recovery.

6.4 Lessons Learned

  • Document timeline, root cause, impact, and corrective actions.
  • Update policies, training, or engineering controls as warranted.

7. Notification Procedures

Deseo Developers LLC maintains defined notification procedures for security incidents. Notifications are coordinated by the Communications Contact / Incident Lead.

7.1 Internal Notification

  • SEV-1 and SEV-2 incidents are escalated immediately to the authorized owner(s).
  • All personnel with relevant system access are informed of containment actions that affect operations.

7.2 Customer / User Notification

  • Where personal data is compromised or law requires notice, affected users are notified without undue delay via email and/or in-product messaging, consistent with the Finducation Privacy Policy.
  • Notifications describe known impact, steps users should take, and contact for questions.

7.3 Partner and Vendor Notification

  • Plaid: Material incidents affecting Plaid API credentials, customer bank-link data obtained via Plaid, or obligations under the Plaid agreement are reported to Plaid through their designated security/partner channels as required by contract.
  • Other subprocessors (Netlify, Supabase, Stripe): notified when their involvement is needed for containment or when contractually required.

7.4 Regulatory Notification

  • Where applicable law (e.g., state breach statutes) requires regulator or AG notice, Deseo Developers LLC will provide required notifications within statutory timeframes.

8. Evidence and Records

  • Incident records include severity, systems affected, containment steps, notifications sent, and closure date.
  • Records are retained according to the Data Retention and Deletion Policy (EZB-RET-001) and legal requirements.

9. Periodic Review

  • This policy is reviewed at least annually and after SEV-1/SEV-2 incidents.
  • Tabletop exercises may be conducted periodically to validate readiness.

10. Related Documents

  • Logging and Monitoring Policy (EZB-LOG-001)
  • Access Control Policy (EZB-ACM-001)
  • Data Retention and Deletion Policy (EZB-RET-001)
  • Finducation Privacy Policy

11. Approval

Approved By: Deseo Developers LLC — Authorized Representative

Date: July 22, 2026

Contact: contact@deseodevelopers.com