Security Documentation

Incident Response

GetBackplate maintains an Incident Response and Breach Notification Protocol governing how we detect, respond to, and communicate about security incidents affecting our Integration product.

Our Approach

Our incident response follows the NIST SP 800-61 framework (Computer Security Incident Handling Guide), adapted to our multi-tenant SaaS architecture and B2B foodservice integration context.

1
Multi-source detection
Automated monitoring (application logs, uptime monitoring, error tracking), customer-reported issues via security@getbackplate.com, and partner notifications from Intuit, Restaurant365, and infrastructure providers.
2
Severity classification with defined SLAs
Every incident is classified by severity (Critical, High, Medium, Low) with corresponding response time commitments ranging from under 1 hour to 72 hours.
3
Structured response phases
Formal phases including detection and analysis, containment, eradication, recovery, and post-incident review, ensuring consistent handling of every incident.
4
Timely customer notification
Affected customers are notified without undue delay, and within 72 hours for confirmed data breaches. Progress updates are provided during active incidents affecting service.
5
Coordinated partner and regulatory notification
Notification to Intuit (QuickBooks® Online), Restaurant365, Stripe, cyber insurance carriers, and regulatory authorities (CCPA, GDPR, state breach notification laws) as required by applicable law and contractual obligations.
6
Post-incident review and continuous improvement
Formal review conducted within 14 days of incident closure, capturing lessons learned, root cause analysis, and improvement actions that update the Protocol and our security controls.

Our Commitments to Customers

Notification Commitments
For any incident materially affecting your data or service, we commit to notification without undue delay. For confirmed data breaches, we commit to customer notification within 72 hours of breach determination. Progress updates are provided every four hours during active Critical or High severity incidents affecting your service.
Recovery Objectives
Our Integration architecture targets an RPO of 24 hours (maximum acceptable data loss) and an RTO of 4 hours (maximum acceptable downtime for critical incidents). These are operational targets, not guarantees, and vary based on incident severity and scope.
Post-Incident Transparency
For Critical incidents affecting customer data, we publish a detailed post-incident summary within 14 days of closure, including timeline, root cause, impact, and corrective actions taken.

Regulatory Compliance

Our Protocol is designed to support compliance with applicable data protection laws and industry frameworks, including:

Reporting a Security Issue

Discovered a potential security issue?
We welcome reports from customers, partners, and security researchers.
security@getbackplate.comAll reports acknowledged within 24 hours

Full Documentation

Our complete Incident Response and Breach Notification Protocol is available under confidentiality to customers, partners, auditors, and regulators upon request. To request access for security review, vendor risk assessment, or compliance evaluation, contact security@getbackplate.com.

Related Documentation