When something goes wrong, we follow a documented process and keep every affected agency informed every step of the way. No surprises. No minimization.
When something goes wrong — whether a security incident, service disruption, or data concern — we follow a documented process and keep affected agencies informed every step of the way.
Our incident response program is built on the same principles as the agencies we serve: clear chain of command, documented procedures, and accountability at every step. We don't minimize incidents — we communicate them honestly.
PulseSafety maintains a written Incident Response Plan that covers detection, containment, eradication, recovery, and post-incident review. Agencies are notified of any confirmed breach involving their data within 24 hours of discovery, consistent with CJIS requirements.
We commit to notifying affected agencies within 24 hours of any confirmed incident involving their data. We will not wait until we have a perfect picture before we reach out.
Every incident — from a service disruption to a confirmed security event — follows the same structured six-phase process.
Automated monitoring, internal reports, and agency notifications feed into our triage queue. Every potential incident is assigned a severity level within one hour of initial detection.
Affected systems are isolated to prevent lateral spread. Temporary controls are put in place while we assess the full scope of the event.
Our engineering and security teams determine root cause, impact scope, and which agencies — if any — were affected. We document findings in real time.
The underlying cause is fully removed. Malicious artifacts are purged, vulnerabilities are patched, and affected credentials are rotated before any systems are restored.
Affected services are restored from clean backups or repaired systems. We monitor closely for recurrence before declaring the incident closed.
Within 5 business days of closure, we complete a written post-mortem documenting what happened, what we did, and what changes we're making to prevent recurrence.
These are not aspirational targets — they are operational commitments backed by our Incident Response Plan.
Every report — internal or external — receives an acknowledgment within one hour of detection or receipt, 24/7/365.
If your agency's data was or may have been involved in a confirmed incident, we will notify your designated contact within 24 hours of confirmation — consistent with CJIS requirements.
A full written post-incident review, including root cause, timeline, impact, and remediation steps, is provided to affected agencies within five business days of incident closure.
Security researchers who report vulnerabilities in good faith will receive a response within one business day. We do not pursue legal action against responsible disclosures.
If you believe you have discovered a security vulnerability, observed anomalous behavior, or need to report a potential incident involving CommandCORE or any PulseSafety system, reach out immediately.
For active deployments, your dedicated success lead can also escalate directly to our security team. Include as much detail as possible — screenshots, log excerpts, affected URLs, timestamps — to help us triage quickly.
Non-urgent security questions, compliance inquiries, and CJIS questionnaire requests can also be sent to the same address. We respond to all security mail within 48 hours.
Our Incident Response program is one layer of a broader security and compliance program. Visit our Security page to learn about our controls, encryption practices, and compliance roadmap.