Standard: Privacy and security incident response
Applies to: Staff, Admins, suppliers, Clients and portal users reporting an incident

Report promptly: exposed links, misdirected files, lost devices, unauthorised access, suspicious exports, credential compromise and accidental disclosure should be reported without waiting for certainty.

1. First response

  1. Stop further disclosure where safe: revoke a link, disable a token, isolate an account or pause an export.
  2. Notify the responsible ClueCheck contact and the relevant Client contact if the project is processed on the Client's instructions.
  3. Preserve limited evidence such as timestamps, URLs, account IDs and actions taken. Do not circulate raw personal data unnecessarily.
  4. Record what happened, which systems and categories may be affected, the likely people affected and the exposure window.

2. Investigation record

QuestionRecord
DetectionWhen and how was it detected, and who became aware?
ContainmentWhat was blocked, revoked, corrected or preserved?
ImpactCategories, individuals, systems, likelihood of access and potential harm.
DecisionNotification, client communication, remediation and lessons learned.
ReviewOwner, deadline, corrective actions and recurrence-prevention check.

3. Reporting route

Use the support route in your portal or contact contact@cluecheck.co.uk with the subject Security Incident. Do not send passwords, full payment-card information or unnecessary identity documents in the first message. The incident owner will coordinate with the Client, supplier, legal adviser or regulator where required.

Related information: Governance Centre · Privacy Governance · Contact ClueCheck