Security

Korven One Incident Response Policy

Korven One is committed to maintaining the security, availability, confidentiality, and integrity of its systems and services. This Policy establishes the procedures for detecting, responding to, investigating, containing, recovering from, and documenting security incidents.

Last updated: Version 1.0 Draft · Effective Date: To Be Determined

1. Purpose

Korven One is committed to maintaining the security, availability, confidentiality, and integrity of its systems and services. This Incident Response Policy establishes the procedures for detecting, responding to, investigating, containing, recovering from, and documenting security incidents.

2. Scope

This Policy applies to:

  • Korven One Infrastructure
  • Applications
  • APIs
  • Databases
  • Wallet Systems
  • Payment Systems
  • Treasury Systems
  • Developer Platforms
  • Cloud Infrastructure
  • Employees
  • Contractors
  • Third-Party Providers

3. Incident Response Objectives

Korven One aims to:

  • Protect customers
  • Protect funds
  • Protect sensitive information
  • Minimize operational disruption
  • Restore services quickly
  • Meet legal obligations
  • Improve security posture

4. Incident Categories

Security Incidents

  • Unauthorized Access
  • Credential Compromise
  • Privilege Escalation
  • Account Takeover

Data Incidents

  • Data Breach
  • Data Exposure
  • Unauthorized Disclosure
  • Information Leakage

Fraud Incidents

  • Fraudulent Transactions
  • Account Abuse
  • Synthetic Identity Activity
  • Payment Fraud

API Incidents

  • API Key Exposure
  • Webhook Compromise
  • Abuse of Developer Services
  • Unauthorized API Activity

Treasury Incidents

  • Unauthorized Transfers
  • Settlement Irregularities
  • Reserve Discrepancies
  • Liquidity Events

Infrastructure Incidents

  • Service Outages
  • DDoS Attacks
  • Cloud Service Failures
  • Network Disruptions

5. Incident Severity Levels

Severity 1 – Critical

  • Active Data Breach
  • Major Treasury Risk
  • Large Scale Fraud
  • Production System Compromise

Target Response: Immediate · 24/7 Escalation

Severity 2 – High

  • Significant Service Disruption
  • Security Control Failure
  • Major API Incident

Target Response: Within Hours

Severity 3 – Medium

  • Limited Service Impact
  • Isolated Fraud Events
  • Individual Account Compromise

Target Response: Business Day Review

Severity 4 – Low

  • Minor Security Events
  • Monitoring Alerts
  • Informational Findings

Target Response: Scheduled Review

6. Incident Response Lifecycle

Korven One follows six phases:

  • Preparation
  • Detection
  • Containment
  • Investigation
  • Recovery
  • Post-Incident Review

7. Preparation

Korven One shall maintain:

  • Monitoring Systems
  • Logging Systems
  • Security Controls
  • Incident Procedures
  • Escalation Contacts
  • Response Tools

Periodic testing may be conducted.

8. Detection

Incidents may be detected through:

  • Monitoring Systems
  • Security Alerts
  • Fraud Detection Systems
  • User Reports
  • Employee Reports
  • Third-Party Notifications

All incidents must be documented.

9. Containment

Korven One may take actions including:

  • Account Restrictions
  • Transaction Holds
  • API Key Revocation
  • Service Isolation
  • Infrastructure Segmentation

Containment actions should prioritize customer protection.

10. Investigation

Korven One may investigate:

  • Root Cause
  • Scope of Impact
  • Affected Systems
  • Affected Data
  • Financial Exposure

Investigations shall be documented.

11. Recovery

Recovery activities may include:

  • Restoring Systems
  • Revalidating Security Controls
  • Reissuing Credentials
  • Restoring Services
  • Reconciliation of Financial Records

Systems shall be verified before returning to normal operations.

12. Communication

Korven One may communicate with:

  • Customers
  • Merchants
  • Developers
  • Partners
  • Service Providers
  • Legal Counsel
  • Regulatory Authorities

Communication shall be coordinated and documented.

13. Fraud Response

Fraud incidents may trigger:

  • Transaction Reviews
  • Account Freezes
  • Enhanced Verification
  • Risk Assessments
  • Escalation Reviews

Fraud investigations may involve compliance personnel.

14. Data Breach Response

Where a data breach is suspected, Korven One may:

  • Contain exposure
  • Investigate affected records
  • Assess legal obligations
  • Notify affected parties when required
  • Implement remediation measures

15. Treasury Incident Response

Treasury-related incidents may require:

  • Immediate Review
  • Dual Approval Verification
  • Settlement Suspension
  • Reserve Verification
  • Executive Escalation

Treasury discrepancies shall be investigated immediately.

16. API Security Incidents

Korven One may:

  • Rotate API Credentials
  • Revoke API Access
  • Restrict Endpoints
  • Increase Monitoring

Developers may be contacted regarding impacted integrations.

17. Third-Party Incidents

Where third-party providers are involved, Korven One may:

  • Coordinate investigations
  • Assess operational impact
  • Implement contingency measures

Third-party risks shall be reviewed periodically.

18. Documentation

Korven One shall maintain records of:

  • Incident Reports
  • Investigation Results
  • Corrective Actions
  • Recovery Activities
  • Lessons Learned

Records shall be retained in accordance with applicable requirements.

19. Post-Incident Review

Following significant incidents, Korven One may conduct:

  • Root Cause Analysis
  • Risk Assessments
  • Security Reviews
  • Process Improvements

Lessons learned shall be incorporated into future controls.

20. Training and Testing

Korven One may conduct:

  • Incident Response Training
  • Security Exercises
  • Tabletop Simulations
  • Recovery Testing

Testing may occur periodically.

21. Governance

Korven One management shall oversee:

  • Incident Reporting
  • Incident Escalation
  • Incident Reviews
  • Risk Management

Significant incidents may be escalated to executive leadership.

22. Policy Updates

Korven One may update this Policy periodically. Updated versions will be published through Korven One services and website.

23. Contact Information

Korven One Security Operations

Email: security@korvenone.com

Email: incident@korvenone.com

Support: support@korvenone.com

Website: https://korvenone.com

24. Language

The official version of this Incident Response Policy is the English version. Translations may be provided in:

  • Haitian Creole
  • French
  • Spanish

In case of conflict, the English version shall prevail.

Questions about this document?

Contact our team at legal@korvenone.com. For security matters, email security@korvenone.com.