SECURITY
Security Incident Reporting
Effective: 5 August 2026 · v1.0 · Owner: Talonic Security
1. Purpose
This page explains how customers can report a suspected security incident affecting Talonic, and what Talonic commits to do in return. It exists to satisfy the AWS Marketplace SaaS security policy requirement for a documented customer incident-reporting process and a customer notification commitment.
2. What counts as a security incident
A security incident is any actual or reasonably suspected unauthorised access to, or unauthorised use, disclosure, alteration, loss or destruction of, customer data or the systems that process it. The notification commitment in section 7 applies from the moment we become aware of an event meeting this definition.
3. How to report a security incident
Email security@talonic.ai with “Security Incident” in the subject line.
If you believe the issue is actively causing harm — for example, unauthorised access to data is ongoing — say so clearly at the top of the email so we can escalate to P1 immediately.
4. What to include in your report
- Whether you believe customer data was exposed, altered, or lost
- Whether the issue appears to be ongoing
- A contact who can answer follow-up questions, and their timezone
Do not include credentials, API keys, or personal data in the body of the email. If evidence contains sensitive material, tell us and we will send you a one-time secure upload link.
5. What happens after you report
- 01Acknowledgement: We confirm receipt within 24 business hours.
- 02Triage: We assess scope, severity, and whether customer data is affected, and we tell you what we have found.
- 03Containment and remediation: We act to stop ongoing harm first, then fix the underlying cause.
- 04Follow-up: Once resolved, we provide a written summary of what happened, what data was affected, and what we changed to prevent recurrence.
6. Severity levels
We triage every report into one of three severity levels. The containment windows below are the targets we work to; acknowledgement and customer notification times in sections 5 and 7 are commitments.
- P1 — Critical: confirmed unauthorised access to customer data, or an incident that is ongoing. Containment work begins immediately on triage; target containment within 24 hours.
- P2 — High: suspected exposure of customer data, or a confirmed incident with no ongoing harm. Target containment within 3 business days.
- P3 — Low: a security-relevant event with no evidence of customer data exposure. Target resolution within 10 business days.
7. Our commitment to notify you
Talonic will notify affected customers of security incidents relevant to them.
Where an incident affects the confidentiality, integrity, or availability of a customer's data, we notify that customer without undue delay and in any case within 72 hours (calendar hours, not business hours) of becoming aware of it.
Notification goes to the customer's designated administrative contact and includes, so far as it is known at the time: what happened, which data categories were involved, what we have done, what we recommend the customer do, and who to contact for more information. Where facts are still emerging, we notify on the basis of what we know rather than waiting for a complete picture, and follow up as the investigation develops.
8. Audit logging
Talonic maintains an audit trail of security-relevant events for each customer. The trail is:
- Append-only: individual audit records cannot be selectively deleted or modified.
- Tamper-evident: records are hash-chained per customer and the chain is anchored daily to external storage, so any modification is detectable.
- Retained for 24 months, then permanently deleted. Audit records are not removed by routine deletion requests.
9. Vulnerability reports
If you have found a vulnerability in Talonic's systems rather than an active incident, report it to security@talonic.ai with “Vulnerability Report” in the subject line. We will acknowledge within 24 business hours.
* Business hours are 09:00 to 18:00 CET, Monday to Friday, excluding German public holidays.
Talonic GmbH · Luisenstr. 53, 10117 Berlin, Germany · security@talonic.ai