Documents / Security Incident Response Policy

Security Incident Response Policy

How we prepare for, handle, and tell you about security incidents.

Version 1.0Effective September 27, 2026Previous versions
This policy explains how Zelari prepares for, handles, and communicates about security incidents. It applies to the Zelari app, our website, and the data we hold for merchants.

1. What counts as a security incident

A security incident is any event that puts the confidentiality, integrity, or availability of Zelari or merchant data at risk. For example:

2. Who is responsible

Zelari's founder is the incident lead and is responsible for running the response, making decisions, and communicating with merchants, Shopify, and our providers. As we grow, this role may be shared with other team members, and we will update this policy when it is.

3. How to report an issue

If you think you have found a security problem, email support@zelari.io with "Security" in the subject line. Please include as much detail as you can, and do not access, change, or share data that isn't yours. We aim to acknowledge reports within 2 business days.

4. Severity levels

LevelMeaning
CriticalMerchant or personal data confirmed exposed, or an attacker has active access
HighData exposure is likely, or Zelari is unavailable for most merchants
MediumA security weakness exists, but there is no sign it has been used
LowA minor issue with little or no risk to data

5. How we respond

  1. Detect and record. We log the report or alert, with the time we became aware of it.
  2. Assess. We confirm what happened and set a severity level.
  3. Contain. We stop the damage from spreading, for example by rotating keys, revoking access, or pausing affected features.
  4. Investigate. We find the cause and work out which merchants and data are affected.
  5. Fix and recover. We remove the cause, restore normal service, and check that the fix works.
  6. Notify. We tell the people who need to know, as described in section 6.
  7. Review. We write up what happened and what we changed so it does not happen again.

6. Who we notify, and when

If we don't yet have all the details, we will share what we know and send updates as we learn more.

7. Records

We keep a record of every security incident, including what happened, its impact, the actions we took, and when we notified people.

8. Prevention

We reduce risk by limiting who can access production data, keeping credentials out of browsers and code repositories, rotating credentials when needed, keeping dependencies up to date, and monitoring for problems.

9. Reviewing this policy

We review this policy at least once a year and after any significant incident.

10. Contact

Security reports: support@zelari.io (use "Security" in the subject line)

Version history

VersionEffectiveSummary
1.0 CurrentSeptember 27, 2026Initial version.

All documents and previous versions