Incident Response

Table of Contents

SoftComply identifies, assesses, investigates and resolves information security incidents that may affect SoftComply applications, systems or information.

Our response approach supports timely escalation, coordinated investigation, appropriate communication and corrective action. The specific response depends on the nature and severity of the incident, the affected product architecture and the respective responsibilities of SoftComply, Atlassian and other relevant service providers.

Incident-Response Process

SoftComply’s incident-response process covers the following activities:

  1. Detection and reporting – Potential incidents may be identified through security alerts, application or platform logs, customer and employee reports, vulnerability disclosures, service-provider notifications or other monitoring channels.

  2. Assessment and classification – The reported event is assessed to determine whether it constitutes a security incident, the systems and information potentially affected, and its likely severity and impact.

  3. Containment – Appropriate measures are taken to limit further exposure, disruption or unauthorised activity. Depending on the circumstances, these measures may include restricting access, disabling affected functionality, rotating credentials or coordinating containment with a service provider.

  4. Investigation – Relevant information is collected and reviewed to establish the nature, scope, cause and impact of the incident. Investigation records and available evidence are preserved in accordance with applicable procedures.

  5. Remediation and recovery – Identified vulnerabilities, configuration issues or other causes are addressed, and affected services are restored when it is considered safe and appropriate to do so.

  6. Communication – Internal and external stakeholders are informed according to the incident’s severity, applicable contractual commitments and legal requirements.

  7. Post-incident review – Material incidents are reviewed to identify root causes, lessons learned and corrective or preventive actions. Relevant policies, controls, systems or training may be updated based on the findings.


Incident Classification and Escalation

Potential incidents are prioritised according to factors such as:

  • The type and sensitivity of the information involved

  • The number and nature of affected customers or users

  • Evidence of unauthorised access, disclosure, alteration or loss

  • The effect on application availability, integrity or confidentiality

  • The likelihood of continued exploitation or harm

  • The potential legal, contractual or regulatory consequences

  • Whether the event affects SoftComply-controlled systems, application code or a third-party platform

Higher-severity incidents are escalated to the personnel responsible for coordinating the investigation, response, customer communication and management decisions. External specialists, legal advisers, regulators, law-enforcement authorities or service providers may be involved where appropriate.


Forge and Atlassian Cloud Incidents

Most SoftComply Cloud applications, are built on Atlassian Forge. Atlassian operates the underlying cloud infrastructure, Forge runtime, physical facilities, network controls and platform-level monitoring.

Where an incident originates from or affects Atlassian Cloud or the Forge platform, SoftComply relies on Atlassian to investigate and remediate the underlying platform issue. SoftComply reviews the information available through Atlassian’s operational and security channels, assesses the potential effect on its applications and customers, and takes application-level and communication actions within its responsibility.

SoftComply remains responsible for investigating and addressing incidents involving its application code, requested permissions, dependencies, SoftComply-controlled systems or internal operations.

Current information about the availability of Atlassian Cloud services is available through the Atlassian Statuspage. Information about Atlassian’s security practices is available through the Atlassian Trust Center.


Other Product Architectures

SoftComply Document Manager has a different architecture that includes backend services hosted in Google Cloud. Incidents affecting those services are investigated and managed in coordination with the relevant cloud service provider where necessary.

SoftComply Data Center applications operate within infrastructure controlled by the customer. Customers are responsible for detecting and responding to incidents affecting their networks, servers, operating systems, databases, Atlassian installations, user accounts and configurations.

SoftComply supports the investigation of suspected vulnerabilities or incidents involving the application code it supplies. Customers should preserve relevant logs and diagnostic information and contact SoftComply as soon as reasonably possible.


Personal-Data Breaches

Where an incident involves personal data, SoftComply assesses whether it constitutes a personal-data breach and determines its responsibilities under applicable data-protection law and contractual arrangements.

SoftComply’s role depends on the affected processing activity. Where SoftComply acts as a controller, SoftComply assesses whether notification to a supervisory authority or affected individuals is required. Where SoftComply acts as a processor, SoftComply informs the relevant customer without undue delay after becoming aware of a personal-data breach, in accordance with the applicable Data Processing Agreement.

A notification may initially be based on incomplete information while the investigation continues. Where appropriate, additional information will be provided in phases as it becomes available.


Customer Notifications

SoftComply notifies affected customers where required by applicable law, contract, Data Processing Agreement, or the nature and impact of the incident. The timing and content of a notification depend on the information available, the severity of the incident and the need to avoid compromising containment or investigation activities.

Where relevant and reasonably available, incident communications may include:

  • A description of the nature of the incident

  • The affected application, service or information

  • The known or likely consequences

  • Containment and remediation actions taken

  • Recommended actions for affected customers

  • A contact point for further information

  • The status of the investigation and expected follow-up

  • Information required under applicable data-protection law or contractual terms

SoftComply may provide updates as the investigation progresses and a closing communication when the incident has been contained and material findings are available.

Sensitive technical, security or personal information may be withheld where its disclosure could create additional risk, affect another party’s rights or compromise an investigation.


Evidence and Record-Keeping

SoftComply maintains records of material security incidents and the actions taken in response. Depending on the incident, records may include reported facts, assessment decisions, investigation findings, communications, remediation activities and post-incident corrective actions.

Relevant evidence is handled in a manner intended to preserve its integrity and restrict access to authorised personnel. Where specialist forensic investigation is required, SoftComply may engage appropriately qualified external support.


Corrective Actions

Following a material incident, SoftComply evaluates whether additional corrective or preventive actions are required. These may include:

  • Application or configuration changes

  • Credential or access-control changes

  • Dependency updates or security patches

  • Additional monitoring or alerting

  • Updates to policies, procedures or technical controls

  • Personnel training or awareness activities

  • Supplier or service-provider follow-up

  • Updates to risk assessments or business-continuity arrangements

Corrective actions are assigned and tracked according to their priority and the risk they are intended to address.


Reporting a Security Incident or Vulnerability

Suspected security incidents and vulnerabilities involving a SoftComply application may be reported through:

Email: support@softcomply.com
Support portal: SoftComply Support Portal

SoftComply’s business hours are 10:00–16:00 CET, Monday to Friday, excluding Estonian national holidays. In accordance with SoftComply’s current Service Level Agreement, support requests receive a response within no more than 24 business hours from the time of submission.

Where a report concerns a suspected security incident or vulnerability, customers should clearly identify this in the subject line or ticket description so that the request can be assessed and escalated appropriately.

The 24-business-hour support response target does not replace any shorter notification or response obligation that may apply under an applicable contract, Data Processing Agreement or law.

An initial report should include, where available:

  • The affected SoftComply application and hosting model

  • The affected Jira or Confluence site, without including unnecessary personal data

  • A description of the observed activity

  • The date and time the issue was identified

  • Steps for reproducing the issue, if applicable

  • Relevant screenshots, error messages or log references

  • Contact information for coordinating the investigation

Do not include passwords, access tokens, private keys or unnecessary personal data in the initial report. SoftComply may provide or agree an appropriate method for exchanging sensitive supporting material.


Responsible Security Testing

Customers and security researchers must obtain prior written authorisation before conducting penetration testing or other active security testing against SoftComply applications or related services.

Testing must not disrupt services, access another customer’s information, compromise user privacy or breach Atlassian’s applicable terms and security-testing requirements.

Potential vulnerabilities should be reported privately and should not be publicly disclosed before SoftComply and the relevant platform provider have had a reasonable opportunity to investigate and address the issue.


Review and Testing

SoftComply reviews its incident-response arrangements periodically and following material incidents or significant changes to its products, services or risk environment. Incident-response and business-continuity procedures may be exercised through tabletop scenarios or other appropriate testing activities.

Lessons identified through incidents, exercises, security assessments and service-provider notifications are considered as part of the continual improvement of SoftComply’s security programme.


Incident-Response Contact

For security incidents, suspected vulnerabilities or questions about SoftComply’s incident-response process, contact support@softcomply.com or use the SoftComply Support Portal.

For privacy-related incidents or personal-data-breach questions, contact privacy@softcomply.com.

Last updated: July 2026