Incident Response

Henex AI Incident Response Policy

Last updated: July 13, 2026

Purpose And Scope

This Policy governs suspected or confirmed events that may affect the confidentiality, integrity, availability, or lawful processing of Henex AI systems or data. It covers security incidents, personal-data breaches, service-provider incidents, credential compromise, unauthorised platform actions, and material availability failures.

Preparation And Reporting

We maintain defined response ownership, access controls, logging, backups, escalation paths, service-provider contacts, and recovery procedures proportionate to our risks. Users and researchers should report suspected incidents promptly to security@henexai.com without accessing or altering data that does not belong to them.

Triage And Containment

We validate reports, preserve relevant evidence, classify severity, assess affected systems and data, and identify whether personal data or customer advertising assets are at risk. Containment may include revoking credentials, isolating services, pausing sensitive actions, blocking malicious traffic, rotating secrets, or engaging a provider.

Investigation, Eradication, And Recovery

Response personnel investigate the cause and scope, remove malicious access or vulnerable components, verify data integrity, restore services in a controlled manner, and monitor for recurrence. Evidence is handled on a need-to-know basis and preserved consistently with legal and regulatory duties.

Notification

We assess notification duties based on risk and applicable law. For a qualifying personal-data breach in Nigeria, Henex AI will notify the Nigeria Data Protection Commission within 72 hours of awareness where the breach is likely to risk individuals' rights and freedoms. Where a breach is likely to create a high risk, we will communicate to affected individuals promptly in clear language, subject to lawful exceptions and regulator directions. Other regulators, customers, insurers, providers, or authorities are notified when required.

Documentation And Improvement

We document the facts, effects, decisions, notifications, and remedial action for personal-data breaches and other material incidents. After containment, we review root cause, control effectiveness, response performance, and corrective actions, then track improvements to completion.

Related Policies

See the Security Policy, Data Processing Policy, and Data Retention Policy for related safeguards and data-handling commitments.

Incident Response Policy | Henex AI