Incident Response
Security incident response process
Effective date: August 25, 2026
Blackwall Systems maintains an incident-response process for suspected or confirmed events that could affect the confidentiality, integrity, or availability of Blackwall systems or personal data.
1. Identification and reporting
Security alerts, anomalous behavior, provider notifications, customer reports, access logs, application errors, and other signals may trigger incident review. Reports are triaged based on potential impact, affected systems, data sensitivity, and likelihood of compromise.
2. Containment
Blackwall may revoke or rotate credentials, disable integrations, restrict accounts, block traffic, isolate affected functionality, suspend automated processing, or take other proportionate measures to limit ongoing exposure.
3. Investigation
Blackwall preserves appropriate evidence and reviews relevant logs, changes, authentication activity, provider information, affected data flows, and system behavior to determine scope and root cause.
4. Eradication and remediation
Confirmed weaknesses are addressed through actions such as patching, configuration changes, credential rotation, access changes, dependency updates, removal of malicious artifacts, or application fixes.
5. Recovery
Affected services are restored in a controlled manner. Recovery may include validation of security controls, monitoring for recurrence, and verification that affected functionality is operating normally.
6. Notification and escalation
Blackwall evaluates legal, contractual, platform, and customer-notification obligations based on the nature of an incident and the data involved. Where required, Blackwall will notify affected merchants, service providers, platforms, regulators, or individuals within applicable timeframes.
7. Documentation and lessons learned
Material incidents are documented with relevant timeline, impact, response actions, and remediation. Blackwall uses incident findings to improve technical controls, procedures, monitoring, and training.
8. Merchant responsibilities
Merchants should promptly report suspected misuse of Blackwall functionality, exposed credentials, unauthorized access, or unusual customer-data behavior and should preserve relevant information that may assist investigation.
9. Reporting a security concern
Use the Blackwall Systems contact form to report a suspected security issue. Do not send passwords, API keys, full payment-card details, or unnecessary customer personal data in the initial report.
