UNDERGROVE
AboutLog inSTART FREE

Data Breach Response Plan

Undergrove · Owner: Reid Brenza · Last reviewed: 12 August 2026

This page is what we've committed to if something goes wrong — what counts as a breach, what you'll be told, and how fast. The operational side (who's called, in what order, how credentials get rotated) is a separate internal document; publishing that would help nobody reading this page and mildly help anyone probing for a way in, so it isn't here. What matters to you — the commitments — is.

What we consider a breach

Unauthorised access to, or disclosure of, personal data — not every anomaly. Not a breach, and not something we'll cry wolf about: a failed login attempt, a blocked scraper, a bug that exposed data to the user it belonged to, or a vulnerability found and fixed with no evidence anyone accessed it.

When genuinely unsure, we treat it as a breach. The cost of an unnecessary notification is our own overcaution. The cost of a missed one is statutory penalties and every affected user finding out we knew first.

Our commitments

We intend to beat the legal minimum, not just meet it:

Who When
Affected users Within 72 hours of confirming a breach
A minor's parent/guardian, where known Same, plus a direct explanation
State Attorneys General As counsel advises, per each state's law
FTC If under-13 data is implicated
Cyber insurer Immediately

All fifty states have breach-notification laws; deadlines and triggers differ by state, and counsel determines the specifics for any given incident. 72 hours is our own working commitment on top of that, not a substitute for it.

What the notice will say

Plain language. No minimising.

  • what happened, and when
  • exactly what data — "essays you uploaded," not "certain user content"
  • what we've done about it
  • what you should do — change your password, watch for phishing
  • how to reach a person: undergrove@undergrovescholar.com
  • an apology, if one is owed

We will not describe a breach affecting a lot of accounts as "a security incident affecting a limited number of accounts." Users forgive breaches. They don't forgive being managed.

After

Within two weeks of any confirmed breach: a written post-mortem — root cause, what worked, what didn't, what changes as a result. The full incident record is retained for 7 years.

TermsPrivacyProtecting Younger Usersundergrove@undergrovescholar.com

UNDERGROVE is an independent search and drafting tool. We do not own, create, fund, administer, judge, or award any scholarship, and we are not affiliated with or endorsed by any provider listed. We never submit applications on your behalf, and we cannot guarantee any award, response, or outcome.