Security Incident Response Policy
Last updated 8/30/2026
ChatiWa Security Incident Response Policy
Version: 1.9.1
Effective Date: June 02, 2026
Owner: BrainGrid Digital (ChatiWa)
Purpose
ChatiWa is committed to protecting merchant and customer data. This Security Incident Response Policy defines how ChatiWa identifies, responds to, investigates, and recovers from security incidents affecting its systems, infrastructure, or customer data.
Scope
This policy applies to:
ChatiWa production systems
Cloud infrastructure
APIs
Databases
Shopify integrations
WhatsApp Business integrations
Internal administrative systems
Employees and authorized contractors with access to ChatiWa systems
Definition of a Security Incident
A security incident includes any event that may compromise the confidentiality, integrity, or availability of ChatiWa systems or customer data, including but not limited to:
Unauthorized access to systems or data
Credential theft or account compromise
Malware or ransomware attacks
Data leaks or accidental exposure
Denial-of-service attacks
Unauthorized API access
Compromised Shopify or WhatsApp credentials
Any suspected breach involving merchant or customer information
Incident Detection
Security incidents may be identified through:
Infrastructure monitoring
Application logs
Error monitoring
Security alerts
Merchant reports
Third-party security notifications
Shopify or Meta security notifications
All suspected incidents are treated as high priority until investigated.
Incident Response Process
1. Identification
The incident is logged and initially assessed to determine:
Type of incident
Affected systems
Potential impact
Severity
2. Containment
Depending on the incident, ChatiWa may:
Disable affected user accounts
Revoke API credentials
Rotate secrets and encryption keys
Block malicious IP addresses
Isolate affected services
Temporarily disable affected integrations
3. Investigation
The security team (or designated administrator) investigates by reviewing:
Application logs
Authentication logs
API activity
Database activity
Infrastructure events
The objective is to determine:
Root cause
Scope
Affected merchants
Affected customer data (if any)
4. Recovery
Recovery activities may include:
Restoring services
Restoring backups when necessary
Applying security patches
Updating infrastructure
Verifying normal operation
Systems are monitored closely after recovery.
5. Notification
If required by law, contractual obligations, or platform requirements, ChatiWa will notify affected merchants of confirmed security incidents involving their data within a reasonable timeframe after investigation.
Notifications include:
Nature of the incident
Potential impact
Actions taken
Recommended merchant actions
6. Post-Incident Review
After every confirmed security incident, ChatiWa performs a review to:
Identify the root cause
Improve detection
Improve response procedures
Implement preventive measures
Update internal documentation where necessary
Data Protection
ChatiWa protects customer information by:
Encrypting sensitive credentials at rest
Using HTTPS/TLS for all communications
Verifying Shopify webhook HMAC signatures
Limiting administrative access
Following the principle of least privilege
Access Control
Only authorized personnel requiring access for operational purposes may access production systems containing merchant or customer information.
Administrative access is reviewed periodically.
Logging and Monitoring
ChatiWa maintains logs for:
Authentication events
Administrative actions
API requests
Integration activity
System errors
Logs assist in detecting, investigating, and responding to security incidents.
Policy Review
This policy is reviewed periodically and updated whenever significant changes occur to ChatiWa's infrastructure, security practices, or applicable legal requirements.
Contact
Security-related concerns may be reported to:
Security Team
Email: security@chatiwa.com