# ETP Foundry — Incident response **Draft v0.1 — pending counsel review · 28 September 2026** How ETP Foundry classifies, handles and discloses incidents. ETP Foundry is operated by one person today. This policy states commitments that one person can keep. ## 1. Severity | Severity | Examples | |---|---| | **S1** | A wrong value published; no value published at a strike; unauthorised access to a system or to personal data; loss of a signing key | | **S2** | A service outage without a wrong value (desk, API, MCP or validator down); a late publication; a failed security control found before exploitation | | **S3** | A defect with no effect on published values or data; a display error on the website | ## 2. Commitments | | S1 | S2 | S3 | |---|---|---|---| | Licensees notified (e-mail) | within **2 hours** of detection | within 1 business day, if they are affected | not required | | Public status entry (etpfoundry.com/status) | within **24 hours** | within 2 business days | in the next update | | Written post-mortem | within **5 business days**, sent to licensees and committee members; a summary is published | on request | not required | ## 3. Procedure 1. **Detect and record** the time found and who found it. 2. **Contain**: stop the strike runner, roll back the service revision, revoke keys or rotate secrets as needed. 3. **Benchmark errors follow the rulebook**: a wrong value is restated as a new record under the same K-of-N quorum and the original is never deleted; a late value keeps its strike time and is labelled late. 4. **Notify** as above. A personal-data breach that creates a real risk of significant harm is also reported to affected individuals and the Office of the Privacy Commissioner of Canada, and a record of every breach is kept, as PIPEDA requires. 5. **Post-mortem**: what happened, impact, root cause, the control added, and what is still open. ## 4. Record Every incident is listed on etpfoundry.com/status with its date and a factual description, and in the quarter's committee minutes. Incidents are not removed from the record once they are fixed. ## 5. Contacts Report a security issue to security@etpfoundry.com. Everything else goes to hello@etpfoundry.com. ## 6. Limits, stated There is no paging tool and no second on-call person. Detection relies on the admin console's alerts and on daily manual checks. The notification times above run from when an incident is detected. Lucilla, Inc., federal corporation no. 16699448, Toronto, trading as ETP Foundry.