Skip to main content

Incident handling

Save Solutions AS has established procedures to detect, handle, and notify security incidents in accordance with GDPR Articles 33 and 34.


Monitoring and detection​

Revizo uses several systems to detect unwanted incidents:

SystemWhat it monitorsAlerting
SentryApplication errors, unexpected exceptions, performance deviationsReal-time alerts to the development team
Structured loggingAll API requests with user ID, organisation ID, and correlation IDReviewed when incidents occur
Audit logSensitive actions: deletion, role changes, integration changes, data exportAvailable to administrators
VercelDeployment status, function errors, response timesAutomatic alerts
SupabaseDatabase health, connections, disk usageDashboard and alerts
Rate limitingUnusually high traffic, potential brute-force attemptsAutomatic blocking with logging

PII protection in monitoring​

The error monitoring system (Sentry) is configured to filter out personal data before data is sent:

  • Request data (request body) is removed automatically
  • Sensitive input is masked in session replay
  • Only error context (type, location in code, correlation ID) is retained

Classification of incidents​

SeverityDescriptionExamplesResponse time
CriticalConfirmed data breach or loss of dataUnauthorised access to customer data, database leakImmediate response
HighPotential security weakness being exploitedSuspicious access pattern, failed authentication attempts at volumeWithin 1 hour
MediumIdentified vulnerability without confirmed exploitationKnown vulnerability in a dependency, configuration errorWithin 24 hours
LowMinor security improvementMissing logging on a non-sensitive routeNext sprint

Response procedure​

When a security incident occurs, we follow this procedure:

1. Identification and containment (0–1 hour)​

  • Confirm that the incident is real (not a false positive)
  • Identify scope: which data, systems, and organisations are affected?
  • Implement containment: block access, rotate keys, disable affected functions

2. Assessment (1–4 hours)​

  • Map cause and attack vector
  • Assess whether personal data has been exposed
  • Document findings continuously
  • Decide whether the incident requires notification (see below)

3. Remediation (4–24 hours)​

  • Implement a permanent fix
  • Verify that the vulnerability is closed
  • Restore normal operation
  • Review whether similar weaknesses exist elsewhere

4. Notification​

Notification to the Norwegian Data Protection Authority (Datatilsynet) (GDPR Art. 33)​

If the incident involves a personal data breach that is likely to result in a risk to data subjects’ rights:

  • Deadline: Within 72 hours after we became aware of the breach
  • Content: Description of the breach, categories and approximate number of those affected, likely consequences, measures taken

Notification to affected customers (GDPR Art. 34)​

If the incident is likely to result in a high risk to data subjects’ rights:

  • Deadline: Without undue delay
  • Channel: Email to all administrators in affected organisations
  • Content: Description of the incident, which data is affected, measures we have taken, recommended measures for the customer

5. Post-evaluation​

  • Internal review of the incident (blameless post-mortem)
  • Identify improvement points in systems, processes, and monitoring
  • Update security documentation and procedures
  • Implement preventive measures

Contact information for incidents​

If you discover a security incident or vulnerability in Revizo, contact us immediately:

We take all security enquiries seriously and reply within 24 hours.

Responsible disclosure​

We encourage security researchers and users to report vulnerabilities responsibly:

  1. Describe the vulnerability in as much detail as possible
  2. Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
  3. Do not share information about the vulnerability with third parties until we have had the opportunity to remediate it
  4. We acknowledge all valid reports and keep you updated on progress

Last updated: March 2026