Security Incident Response
Last Updated: July 2026
Our Commitment to Security
Central Alberta After Dark takes security seriously. We have implemented comprehensive measures to protect your data and maintain the integrity of our platform. This document outlines how we detect, respond to, and recover from security incidents.
1. What Constitutes a Security Incident
A security incident includes but is not limited to:
- Data Breach: Unauthorized access to user data, including personal information, messages, or payment details
- System Compromise: Unauthorized access to our servers, databases, or infrastructure
- Service Disruption: Attacks that affect the availability of our services (DDoS, etc.)
- Malware or Hacking: Detection of malicious code or unauthorized system modifications
- Account Takeover: Evidence of unauthorized access to user accounts
- Phishing or Social Engineering: Attempts to impersonate our platform or staff
2. Incident Detection & Monitoring
We employ multiple layers of security monitoring:
- Real-time Log Analysis: Automated monitoring of security logs 24/7
- Intrusion Detection: Systems to detect unauthorized access attempts
- Rate Limiting Alerts: Notifications when unusual patterns are detected
- Session Anomaly Detection: Identification of suspicious login patterns
- File Integrity Monitoring: Detection of unauthorized changes to critical files
3. Incident Response Process
Phase 1: Detection & Analysis (0-4 hours)
- Confirm the incident and assess severity
- Identify affected systems and data
- Determine scope of potential impact
- Preserve evidence for investigation
Phase 2: Containment (4-24 hours)
- Isolate affected systems if necessary
- Block ongoing attack vectors
- Reset compromised credentials
- Implement temporary safeguards
Phase 3: Eradication & Recovery (24-72 hours)
- Remove malicious code or access points
- Restore systems from clean backups
- Verify integrity of restored systems
- Gradually restore full service
Phase 4: Post-Incident Review (1-4 weeks)
- Document lessons learned
- Update security measures
- Notify affected users as required
- Report to authorities if necessary
4. Notification Procedures
Internal Notification
Security incidents are reported to:
- System administrators (immediate)
- Management (within 1 hour)
- Legal counsel (within 4 hours)
External Notification (PIPEDA Requirements)
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA):
- Affected Users: We will notify affected users within 72 hours of confirming a breach
- Privacy Commissioner: We will report to the Office of the Privacy Commissioner of Canada (OPC) as required
- Other Authorities: Law enforcement and other relevant authorities as required by law
⚠️ Timeframe for Notification
We aim to notify affected users within 72 hours of discovering a breach that poses a real risk of significant harm. For EU/EEA users under GDPR Article 33, notification to supervisory authorities occurs within 72 hours.
5. User Notification Content
When we notify you of a security incident, we will provide:
- Description of the Incident: What happened and when
- Data Affected: What information was potentially compromised
- Potential Impact: What risks you may face
- Protective Measures: Steps you should take to protect yourself
- Our Actions: What we are doing to address the situation
- Contact Information: How to reach us for questions or concerns
6. Recommended Actions for Users
If you believe your account has been compromised:
- Change Your Password Immediately: Use a strong, unique password
- Enable Email Verification: Ensure your email is verified and secure
- Review Account Activity: Check for any unauthorized actions
- Update Other Accounts: If you used the same password elsewhere, change it
- Monitor Financial Statements: Watch for unauthorized transactions
- Report to Us: Contact centralalbertaafterdarkads@gmail.com
7. Data Backup & Recovery
Our data backup and recovery procedures include:
- Daily Backups: Complete database backups performed daily
- Secure Storage: Backups stored in encrypted, geographically separate locations
- Regular Testing: Backup restoration procedures tested quarterly
- Point-in-Time Recovery: Ability to restore to specific points in time
- Retention Policy: Backups retained according to data retention requirements
8. Security Measures in Place
We implement industry-standard security measures:
- Encryption in Transit: HTTPS/TLS encryption for all data transmission
- Encryption at Rest: Sensitive data encrypted in our databases
- Access Controls: Strict access controls limiting who can access user data
- Security Headers: HSTS, CSP, X-Frame-Options, and other protective headers
- Input Validation: All user input sanitized and validated
- Parameterized Queries: SQL injection prevention
- CSRF Protection: Tokens on all state-changing requests
- Rate Limiting: Protection against brute force and abuse
9. Reporting a Security Vulnerability
If you discover a security vulnerability in our platform, we encourage responsible disclosure:
Report Security Vulnerabilities to:
security@centralalbertaafterdark.com
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any proof-of-concept (if applicable)
Our Commitment to Researchers:
- We will acknowledge receipt within 48 hours
- We will provide regular updates on remediation progress
- We will credit researchers who responsibly disclose vulnerabilities (with permission)
- We will not take legal action against good-faith security researchers
10. Contact Information
For security-related inquiries:
Security Team
security@centralalbertaafterdark.com
Response Time: Within 24-48 hours for non-urgent matters
For urgent incidents: Same-day response during business hours
For general support and account-related issues:
Email: centralalbertaafterdarkads@gmail.com
Response Time: Within 30 days as per PIPEDA requirements
11. Related Policies
For more information, please review:
- Privacy Policy - How we protect your data
- Terms of Service - Our legal agreement
- Community Guidelines - Platform rules
- Accessibility Statement - Our accessibility commitments