Data breach

What to do when personal data handled by the Relay may have been exposed. The GDPR clock is 72 hours from becoming aware (Art. 33).

Detect

Breaches surface through infra alerts, a security disclosure, or a notice from a processor. Processors are obliged to tell us without undue delay.

Contain

  1. Rotate the affected secret. Runbooks: token key, relay key, grant key, database key.
  2. Revoke compromised wallets if credit tokens leaked.
  3. Preserve logs in Cockpit before they age out.

Assess

Record what was exposed, when, and how many wallets were affected. The Relay holds no identities and no content, so the likely categories are credit tokens, wallet balances, and IP addresses in logs. See the GDPR assessment for what exists.

Notify

Risk to personsAction
UnlikelyRecord internally only (Art. 33(5))
LikelyNotify Datatilsynet within 72 hours (Art. 33)
HighAlso inform users (Art. 34). The Relay cannot contact users directly, so publish a notice on eigin.ai and in the App

Record

Every breach, reported or not, goes in a confidential GitLab issue with the security label: facts, effects, and remedial action.