Skip to content
Legal Center

KokuaOS — Incident Response Policy

Effective July 18, 2026 · Version 1.0

A public summary of how KokuaOS detects, responds to, and communicates about security incidents, and what customers are expected to do.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Purpose and scope

This Policy summarizes, at a high level, how KokuaOS prepares for and responds to security incidents affecting the Platform, the Services, or the data KokuaOS processes. It is written for a public audience and does not disclose confidential defensive details. In this Policy, a "security incident" means a confirmed unauthorized access to, or unauthorized acquisition, loss, alteration, disclosure, or destruction of, Customer Data or KokuaOS systems that materially affects the confidentiality, integrity, or availability of the Services or such data. Not every alert, anomaly, unsuccessful attempt, or routine security event is a security incident. This Policy is a description of practices; it does not create obligations beyond, and does not modify, the Agreement or any Data Processing Addendum, which control over this Policy where they address the same subject.

2. Preparation

KokuaOS maintains a documented incident-response plan with defined roles and responsibilities, an internal escalation path, and periodic review and exercising of the plan. This capability works together with the controls described in the Security Policy (kokuaos.com/legal/security).

3. Detection and triage

KokuaOS uses logging, monitoring, and alerting, together with reports from personnel, customers, and external researchers, to identify potential security incidents. When a potential incident is identified, KokuaOS triages it to confirm whether an incident has occurred and to assign a severity based on factors such as the sensitivity of the data involved, the scope and number of affected tenants, and the potential impact to the Services and to individuals.

4. Containment

Upon confirming an incident, KokuaOS takes steps reasonably designed to contain it and limit its impact — for example, isolating affected systems, revoking or rotating credentials and keys, blocking malicious activity, and applying temporary mitigations — balancing rapid containment against the need to preserve evidence for investigation.

5. Investigation

KokuaOS investigates confirmed incidents to determine, as reasonably practicable, the nature and root cause, the systems and data affected, and the parties who may be impacted. Investigations may involve internal teams and qualified third-party specialists, and may be conducted in coordination with legal counsel.

6. Eradication, remediation, and recovery

KokuaOS works to remove the cause of the incident, remediate exploited weaknesses, and restore affected Services to normal operation from trusted sources, including validating the integrity of restored systems and data before returning them to production. Recovery steps are prioritized by risk and impact.

7. Customer notification

Where KokuaOS determines that a security incident affects a customer's Customer Data, KokuaOS will notify affected customers where legally or contractually required. Notification will be made without undue delay and as required by applicable law or the applicable Data Processing Addendum, and will be delivered to the administrative or security contact on file or by another reasonable means. Where a Data Processing Addendum specifies a notification timeframe, content, or process, that Addendum controls. Nothing in this Policy commits KokuaOS to a notification timeframe or standard broader than applicable law or a signed Data Processing Addendum requires. Notifications will provide the information KokuaOS is able to confirm at the time and may be supplemented as the investigation progresses; an initial notification is not an acknowledgment of fault or liability. Because KokuaOS generally acts as a processor/service provider for Customer end-user data, the Customer, as controller/business, is responsible for any notifications to end users, regulators, or other third parties, unless the Data Processing Addendum states otherwise; KokuaOS will provide reasonable cooperation and information to support those obligations.

8. Evidence preservation

KokuaOS seeks to preserve relevant logs, artifacts, and other evidence in a manner reasonably designed to maintain their integrity, to support investigation, remediation, legal obligations, and any subsequent review, consistent with its retention practices and applicable law.

9. Coordinated communications

To ensure accuracy, KokuaOS coordinates external communications about an incident through authorized personnel and its established channels, including the Trust Center (/trust) where appropriate. Customers should likewise coordinate with KokuaOS before making public statements that identify KokuaOS in connection with an incident, and should treat non-public incident information as Confidential Information under the Agreement.

10. Post-incident review

After a significant incident is resolved, KokuaOS conducts a post-incident review to identify root causes, lessons learned, and improvements to controls and to this response process, and to track resulting remediation items to completion.

11. Customer and partner responsibilities

Effective incident response depends on customers as well. Customers, Service Providers, Resellers, and their Authorized Users must:

  • promptly report suspected security incidents, compromised or lost credentials, suspicious activity, or vulnerabilities affecting the Services to security@kokuaos.com;
  • safeguard and promptly rotate or revoke credentials, API keys, and access on suspected compromise, and maintain appropriate security for their own systems, endpoints, integrations, and BYO Providers;
  • reasonably cooperate with KokuaOS in the investigation and remediation of an incident, including providing relevant information; and
  • maintain their own incident-response and notification capabilities for their environment and end users, including for incidents originating in customer-controlled systems or BYO Providers, which are the responsibility of the customer.

12. Relationship to other documents

This Policy works together with the Security Policy (kokuaos.com/legal/security), the Vulnerability Disclosure Policy (kokuaos.com/legal/vulnerability-disclosure), the Privacy Policy (kokuaos.com/legal/privacy), and any executed Data Processing Addendum (kokuaos.com/legal/dpa). The disclaimers and limitations of liability in the Agreement, and the responsibility for BYO Providers described in the BYO Provider Policy (kokuaos.com/legal/byo-providers), apply to incidents and are not modified by this Policy.

13. Updates and contact

KokuaOS may update this Policy from time to time as described in the Master Terms & Conditions. To report a suspected incident, contact security@kokuaos.com. The current version of this Policy is published at /legal/incident-response.

See it liveBook a demo