Incident handling
Save Solutions AS has established procedures to detect, handle, and notify security incidents in accordance with GDPR Articles 33 and 34.
Monitoring and detection
Revizo uses several systems to detect unwanted incidents:
| System | What it monitors | Alerting |
|---|---|---|
| Sentry | Application errors, unexpected exceptions, performance deviations | Real-time alerts to the development team |
| Structured logging | All API requests with user ID, organisation ID, and correlation ID | Reviewed when incidents occur |
| Audit log | Sensitive actions: deletion, role changes, integration changes, data export | Available to administrators |
| Vercel | Deployment status, function errors, response times | Automatic alerts |
| Supabase | Database health, connections, disk usage | Dashboard and alerts |
| Rate limiting | Unusually high traffic, potential brute-force attempts | Automatic blocking with logging |
PII protection in monitoring
The error monitoring system (Sentry) is configured to filter out personal data before data is sent:
- Request data (request body) is removed automatically
- Sensitive input is masked in session replay
- Only error context (type, location in code, correlation ID) is retained
Classification of incidents
| Severity | Description | Examples | Response time |
|---|---|---|---|
| Critical | Confirmed data breach or loss of data | Unauthorised access to customer data, database leak | Immediate response |
| High | Potential security weakness being exploited | Suspicious access pattern, failed authentication attempts at volume | Within 1 hour |
| Medium | Identified vulnerability without confirmed exploitation | Known vulnerability in a dependency, configuration error | Within 24 hours |
| Low | Minor security improvement | Missing logging on a non-sensitive route | Next sprint |
Response procedure
When a security incident occurs, we follow this procedure:
1. Identification and containment (0–1 hour)
- Confirm that the incident is real (not a false positive)
- Identify scope: which data, systems, and organisations are affected?
- Implement containment: block access, rotate keys, disable affected functions
2. Assessment (1–4 hours)
- Map cause and attack vector
- Assess whether personal data has been exposed
- Document findings continuously
- Decide whether the incident requires notification (see below)
3. Remediation (4–24 hours)
- Implement a permanent fix
- Verify that the vulnerability is closed
- Restore normal operation
- Review whether similar weaknesses exist elsewhere
4. Notification
Notification to the Norwegian Data Protection Authority (Datatilsynet) (GDPR Art. 33)
If the incident involves a personal data breach that is likely to result in a risk to data subjects’ rights:
- Deadline: Within 72 hours after we became aware of the breach
- Content: Description of the breach, categories and approximate number of those affected, likely consequences, measures taken
Notification to affected customers (GDPR Art. 34)
If the incident is likely to result in a high risk to data subjects’ rights:
- Deadline: Without undue delay
- Channel: Email to all administrators in affected organisations
- Content: Description of the incident, which data is affected, measures we have taken, recommended measures for the customer
5. Post-evaluation
- Internal review of the incident (blameless post-mortem)
- Identify improvement points in systems, processes, and monitoring
- Update security documentation and procedures
- Implement preventive measures
Contact information for incidents
If you discover a security incident or vulnerability in Revizo, contact us immediately:
- Email: karl@savesolutions.no
- Subject: SECURITY INCIDENT — [short description]
We take all security enquiries seriously and reply within 24 hours.
Responsible disclosure
We encourage security researchers and users to report vulnerabilities responsibly:
- Describe the vulnerability in as much detail as possible
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
- Do not share information about the vulnerability with third parties until we have had the opportunity to remediate it
- We acknowledge all valid reports and keep you updated on progress
Last updated: March 2026