← All legal documents

Truefold — Incident Response Summary

Version 1.0 — Effective 2026-08-27 · Published at truefold.ai/legal/incident-response

Last updated: 2026-08-28

This is the public summary of how Truefold detects, contains and reports security incidents. It satisfies Shopify's Level 2 protected-customer-data requirement for a security incident response policy and implements the notification commitments in the Merchant Data Processing Agreement (§ 8). The full internal policy is available to merchants on request under DPA § 11. Truefold is operated by Auke Vos, Mexico. Questions: privacy@truefold.ai.

How we classify incidents

We rank severity by impact on the confidentiality, integrity or availability of merchant data. The most serious tier — confirmed or suspected unauthorised access to Customer Data, credentials, or cross-tenant access — is treated as a personal data breach unless and until it is ruled out. When in doubt, we classify up. A suspected compromise of Merchant Data is enough to start the reporting clock, before anything is confirmed.

How we detect them

Incidents surface from several independent sources:

  • Error and exception monitoring across the backend and web app (with personal data excluded from reports).
  • Platform logs from our hosting and database providers, and our own redacted query and AI-call logs.
  • BigQuery Data Access audit logs on the project that holds Customer Data — the authoritative record of who accessed merchant data.
  • Automated CI security gates on every change: secret scanning, dependency-vulnerability audits, and static analysis.
  • Breach notifications from our sub-processors, and reports to privacy@truefold.ai (monitored daily), Shopify Partner channels, and in-app.

The awareness clock for every deadline below starts the moment we have a reasonable degree of certainty that an incident has occurred — including on reading a sub-processor's notice or an external report.

How we respond

Every incident runs through four phases, with a timestamped log kept from the first minute:

  1. Triage (target: within 1 hour of awareness) — record the awareness time, assign severity, establish which systems, data categories and merchants are affected, and decide immediately whether the 24-hour Shopify notification is in scope.
  2. Containment — revoke and rotate affected credentials, cut data-plane and user access to the affected surface, and preserve logs and evidence before they rotate.
  3. Assessment and eradication — determine root cause and the exact blast radius (per-merchant dataset isolation makes the set of affected merchants enumerable; our minimised schema means no plaintext names, emails, addresses, phone numbers or IP addresses exist to lose), fix and verify, and restore service.
  4. Notification and closure — execute the notifications below, then write a post-incident review and close out any control gaps it exposed.

Who we notify, and when

All clocks run from the recorded awareness time and run in parallel — we send a preliminary notice within each window even if the facts are still incomplete, and supplement as we learn more.

WhoWhenTrigger
ShopifyWithin 24 hoursAny actual or suspected breach or compromise of Merchant Data
Affected merchantsWithout undue delay, within 48 hoursA personal data breach affecting their Customer Data
All merchantsPromptlyPlatform-wide incidents affecting trust in the service

Notifying merchants within 48 hours is designed to preserve each merchant's own margin on the GDPR Article 33 72-hour clock to their supervisory authority — that clock is the merchant's to run, and our job is to start it early and feed it facts. Where Mexican law applies, Truefold acts as encargado for Customer Data and assists the merchant's obligations; for Truefold's own account data it notifies affected users directly.

What we never do

We never pay extortion demands, never delete or overwrite evidence, and never downplay a suspected breach below the Shopify 24-hour threshold to avoid reporting. Over-notification is the accepted cost of the doubt. We make no public statement before affected parties are notified, and we never confirm incident details to unverified parties.

Review

This policy is reviewed at least annually and after any material architecture change, including a yearly tabletop walkthrough of a realistic breach scenario. Every qualifying incident is recorded in a private incident register, available to merchants' auditors in redacted form under DPA § 11.