Data Breach Response Plan
Undergrove · Owner: Reid Brenza · Last reviewed: 12 August 2026
This page is what we've committed to if something goes wrong — what counts as a breach, what you'll be told, and how fast. The operational side (who's called, in what order, how credentials get rotated) is a separate internal document; publishing that would help nobody reading this page and mildly help anyone probing for a way in, so it isn't here. What matters to you — the commitments — is.
What we consider a breach
Unauthorised access to, or disclosure of, personal data — not every anomaly. Not a breach, and not something we'll cry wolf about: a failed login attempt, a blocked scraper, a bug that exposed data to the user it belonged to, or a vulnerability found and fixed with no evidence anyone accessed it.
When genuinely unsure, we treat it as a breach. The cost of an unnecessary notification is our own overcaution. The cost of a missed one is statutory penalties and every affected user finding out we knew first.
Our commitments
We intend to beat the legal minimum, not just meet it:
| Who | When |
|---|---|
| Affected users | Within 72 hours of confirming a breach |
| A minor's parent/guardian, where known | Same, plus a direct explanation |
| State Attorneys General | As counsel advises, per each state's law |
| FTC | If under-13 data is implicated |
| Cyber insurer | Immediately |
All fifty states have breach-notification laws; deadlines and triggers differ by state, and counsel determines the specifics for any given incident. 72 hours is our own working commitment on top of that, not a substitute for it.
What the notice will say
Plain language. No minimising.
- what happened, and when
- exactly what data — "essays you uploaded," not "certain user content"
- what we've done about it
- what you should do — change your password, watch for phishing
- how to reach a person: undergrove@undergrovescholar.com
- an apology, if one is owed
We will not describe a breach affecting a lot of accounts as "a security incident affecting a limited number of accounts." Users forgive breaches. They don't forgive being managed.
After
Within two weeks of any confirmed breach: a written post-mortem — root cause, what worked, what didn't, what changes as a result. The full incident record is retained for 7 years.