← Security & Trust

Incident Response Policy

Fueling Agile Nigeria · Effective 1 January 2026 · Next review 18 January 2027
Owner: David Owolabi · Contact: fuelingagilenigeria@gmail.com (24×7 best-effort for production-impacting incidents)

1. Purpose

Define how we detect, contain, investigate, and learn from security incidents affecting AgileFlex / FANMS or customer data.

2. What counts as an incident

Suspicious fuel transactions flagged by product rules are business fraud alerts. They become security incidents when they involve system compromise or unauthorized access.

3. Severity

LevelMeaningResponse target
P1 — CriticalActive breach, data exfiltration, or production down due to attackImmediate; all-hands
P2 — HighLikely compromise or sensitive secret exposureSame business day
P3 — MediumContained abuse, failed attack with lasting riskWithin 2 business days
P4 — LowPolicy violation or hardening gap without evidence of exploitPlanned fix

4. Response steps

  1. Detect & report — Anyone can report to fuelingagilenigeria@gmail.com. Include time, what happened, systems involved, and whether customer data may be affected.
  2. Triage — David Owolabi (or delegate) assigns severity and an incident owner.
  3. Contain — Revoke sessions; disable accounts; rotate exposed secrets; block abusive IPs at the edge if needed.
  4. Eradicate — Remove the cause (patch, revoke keys, fix misconfiguration).
  5. Recover — Restore service from known-good deploys/backups; verify auth and audit trails.
  6. Notify — Inform affected customers and, where legally required, authorities. Do not speculate publicly.
  7. Learn — Write a short post-incident note: timeline, root cause, what we change, owner, due date.

5. Evidence we can use

Preserve logs before rotating or deleting during an investigation.

6. Communication rules

7. Enforcement and drills

Related: Information Security · Access Control · Data Protection