warning

Data Breach Response

While we implement stringent security measures, we recognize that no system is entirely immune to threats. This page outlines our structured incident response framework to detect, mitigate, and report security incidents swiftly and transparently.

1. Detection and Classification

Our automated monitoring systems and SOC are configured to detect anomalous activities. Upon detection, incidents are immediately classified by severity (Low, Medium, High, Critical). Any incident involving unauthorized access, disclosure, or loss of personal data is classified as a "Data Breach" and escalated to our Data Protection Officer (DPO).

2. Containment and Mitigation

Our primary objective during an active incident is containment. Our engineering team has the authority to immediately isolate affected systems, revoke compromised credentials, or take vulnerable services offline to prevent further data exposure.

3. Notification Timelines (CERT-In Compliance)

NowMeLive strictly adheres to the incident reporting guidelines set by the Indian Computer Emergency Response Team (CERT-In).

  • Regulatory Reporting: We will report severe cyber security incidents (as defined by CERT-In) to the relevant authorities within 6 hours of noticing the incident.
  • Merchant Notification: If a breach impacts your organization data, we will notify the primary administrator of your account without undue delay, providing details on the nature of the breach, the data affected, and the mitigation steps taken.

4. Post-Incident Review

Following the containment of any critical incident, we conduct a comprehensive Root Cause Analysis (RCA). We use these findings to patch vulnerabilities, improve our detection systems, and publish a transparent post-mortem report for affected Merchants.