Incident Response Plan
Detecting, containing, and recovering from security incidents
Last updated June 20, 2026
This plan outlines how HEXANGO PRIVATE LIMITED responds to security incidents affecting foretale.ai or customer data.
Objectives
Minimize impact to customers, preserve evidence, restore services promptly, and meet applicable legal and contractual notification obligations.
Incident classification
Incidents are classified by severity to determine response urgency.
- Critical: Confirmed unauthorized access to customer data or production systems.
- High: Active exploitation attempt, service-wide outage with security impact.
- Medium: Suspected vulnerability with plausible exploit path.
- Low: Policy violations, phishing attempts, or non-exploitable findings.
Response phases
Our response follows industry-standard phases:
- Detection & analysis — Triage alerts, logs, and reports; assign incident lead.
- Containment — Isolate affected systems; revoke compromised credentials.
- Eradication — Remove threat; patch vulnerabilities; rotate secrets.
- Recovery — Restore services; validate integrity; resume normal operations.
- Post-incident — Root cause analysis, customer notification if required, lessons learned.
Communication
Affected customers are notified without undue delay when their data is reasonably believed to be compromised, in accordance with applicable law and contractual commitments. Status updates are provided through designated customer contacts.
Reporting security issues
External researchers and customers may report vulnerabilities or incidents to contact@hexango.com. See our Vulnerability Disclosure page for coordinated disclosure guidelines.