Breadcrumbs

Information Security Incident Management Policy

Effective date: 1.8.2026


Purpose

Circularo is committed to protecting the confidentiality, integrity, and availability of customer and company information. This policy describes our principles for identifying, managing, responding to, and learning from information security incidents.

Our objective is to:

  • protect customers and business operations,

  • minimize the impact of security incidents,

  • comply with applicable legal and regulatory requirements,

  • continuously improve our security management processes.

Scope

This policy applies to all Circularo services, employees, contractors, and third parties involved in delivering or supporting our products and services.

Incident Management Principles

Circularo follows a structured incident management process designed to ensure that security events are handled consistently and efficiently.

The process includes:

  • detection and reporting,

  • assessment and classification,

  • containment and mitigation,

  • investigation,

  • recovery,

  • post-incident review,

  • implementation of corrective and preventive actions.

Incident Reporting

Security incidents may be identified through:

  • internal monitoring,

  • automated security systems,

  • employees,

  • customers,

  • business partners,

  • external researchers.

All reported incidents are evaluated by authorized personnel and handled according to their potential business and security impact.

Incident Response

When an incident is confirmed, Circularo will:

  • assess its scope and severity,

  • initiate appropriate containment measures,

  • investigate the root cause,

  • restore affected services,

  • preserve relevant evidence,

  • document the incident,

  • implement improvements to reduce the likelihood of recurrence.

Root Cause Analysis

Significant security incidents are subject to a formal Root Cause Analysis (RCA).

The purpose of the RCA process is to:

  • identify the underlying causes,

  • evaluate contributing factors,

  • define corrective and preventive actions,

  • improve operational resilience.

Customer Communication

Where appropriate, Circularo communicates relevant information to affected customers in accordance with contractual obligations and applicable laws.

Communications may include:

  • description of the incident,

  • affected services,

  • mitigation measures,

  • recovery status,

  • recommended customer actions (if applicable).

Regulatory Compliance

Where required by applicable legislation, Circularo notifies competent supervisory authorities and affected individuals within the legally required timeframes.

Continuous Improvement

Lessons learned from incidents are incorporated into:

  • security controls,

  • technical safeguards,

  • employee awareness,

  • operational procedures,

  • risk management activities

Governance

This policy forms part of Circularo's Information Security Management System (ISMS) and supports our commitment to internationally recognized security standards, including ISO/IEC 27001.

The policy is reviewed periodically and updated as necessary.

Contact

Security concerns or vulnerability reports may be submitted to:

security@circularo.com