Effective August 18, 2026 · Version 1.0
Security incident response
BroFam maintains a process to identify, contain, investigate, remediate, document, and learn from suspected security or personal-data incidents affecting BroFam applications.
Reporting
Report suspected vulnerabilities or incidents to contact form. Include the affected application, time observed, safe reproduction details, and potential impact. Do not send credentials, access tokens, or customer personal data by ordinary email.
Response process
BroFam triages reports, assigns severity and ownership, preserves PII-minimized evidence, contains affected access or workloads, determines scope and affected tenants, remediates the cause, validates recovery, and records follow-up actions. Credentials are revoked or rotated when compromise is suspected. Privacy, application, infrastructure, and merchant responsibilities are coordinated according to the incident.
Notification
BroFam notifies affected merchants and required providers or authorities without undue delay after confirming a reportable incident. Notices describe known timing, data and tenants affected, likely consequences, containment, remediation, and a contact for follow-up, as information becomes available. BroFam does not delay urgent containment while completing the investigation.
Recovery and review
Recovery uses verified infrastructure and application state. BroFam monitors for recurrence and conducts a post-incident review for material events, tracking corrective actions to completion. Public statements and legal notices are coordinated to avoid exposing personal data or security-sensitive details.
Scope
This page states BroFam’s incident commitment; operational contacts, credentials, evidence locations, and response commands remain access-controlled. It does not claim a third-party certification.
Change history
Version 1.0 — initial incident-response commitment published August 18, 2026.