Data breach
What to do when personal data handled by the Relay may have been exposed. The GDPR clock is 72 hours from becoming aware (Art. 33).
Detect
Breaches surface through infra alerts, a security disclosure, or a notice from a processor. Processors are obliged to tell us without undue delay.
Contain
- Rotate the affected secret. Runbooks: token key, relay key, grant key, database key.
- Revoke compromised wallets if credit tokens leaked.
- Preserve logs in Cockpit before they age out.
Assess
Record what was exposed, when, and how many wallets were affected. The Relay holds no identities and no content, so the likely categories are credit tokens, wallet balances, and IP addresses in logs. See the GDPR assessment for what exists.
Notify
| Risk to persons | Action |
|---|---|
| Unlikely | Record internally only (Art. 33(5)) |
| Likely | Notify Datatilsynet within 72 hours (Art. 33) |
| High | Also inform users (Art. 34). The Relay cannot contact users directly, so publish a notice on eigin.ai and in the App |
Record
Every breach, reported or not, goes in a confidential GitLab issue with the security label: facts, effects, and remedial action.