Incident Response & Security Notification Policy
Version 1.1Current Official ReleaseEffective Date: 2026-08-04 · Last Updated: 2026-08-04
Incident Response & Security Notification Policy
Effective Date: July 31, 2026 Last Updated: July 31, 2026 Version: 1.0
Purpose
This policy describes how Dominus Energy Group LLC identifies, responds to, and communicates about security incidents affecting Donnas-Bandwidth-Booster™. It complements the Security Statement and Data Retention Policy.
What We Consider a Security Incident
A security incident is any confirmed event that compromises, or has a realistic potential to compromise, the confidentiality, integrity, or availability of user data or the Service. Examples include unauthorized access to an account or system, exposure of sensitive data, or successful exploitation of a vulnerability.
Detection
We rely on a combination of access controls, audit logging (see Security & Privacy Overview), and reports submitted through our Security Vulnerability Reporting channel to identify potential incidents.
Response Process
When a potential incident is identified, our process is to:
1. Confirm and contain — verify the report or alert, and take immediate steps to limit further exposure (for example, revoking affected credentials or tokens). 2. Assess — determine what data or systems were affected and the scope of impact. 3. Remediate — fix the underlying cause. 4. Notify — where notification is warranted (see below), inform affected users and, where legally required, applicable regulators. 5. Review — evaluate what changes to our practices, if any, would reduce the likelihood of recurrence.
Notification
If we determine that a security incident has resulted in unauthorized access to your personal data, we will notify affected users without undue delay after confirming the incident, using the contact information associated with your account or, where applicable, through an in-app notice. Specific statutory notification timelines and required notice contents vary by jurisdiction; Dominus Energy Group LLC will comply with all applicable legal requirements for breach notification in each jurisdiction where the Service is offered.
Your Role
If you believe your account has been compromised, or you notice suspicious activity, please contact us immediately using the Security Vulnerability Reporting contact in Contact Information.
Coordination With Researchers
We welcome good-faith security research conducted within the bounds of an approved engagement, as described in our Acceptable Use Policy. We ask researchers to report findings to us privately and to give us a reasonable opportunity to remediate before any public disclosure.
Changes to This Policy
We may update this policy as our incident response practices evolve. Material changes will be reflected in the "Last Updated" date above.
Contact
Questions about this policy, or reports of a suspected incident, can be directed to us using the Security Vulnerability Reporting contact in Contact Information.