TRUST CENTER · INCIDENT RESPONSE · NO ON-CALL, NO PRETENDING

When something breaks,
here is what happens.

wrxstack is run by one person. There is no on-call rotation, no severity paging, and no incident history to publish. This page says what actually happens when something goes wrong, the one obligation the law puts on us, and what we commit to afterward.

Live status Trust Centercontact@wrxstack.com
01 / What actually happens

One person fixes it.

There is no rotation to page and no bridge call to open. When wrxstack breaks, one person notices it or is told about it, works out what is wrong, fixes it, and tells the people it affected. That is the whole process, described honestly.

How we find out
Someone notices, or you tell us. Either the site's own checks or a message from you. There is no 24/7 monitoring desk. If you see something broken, email contact@wrxstack.com and it reaches the person who can fix it.
Who responds
The same person who builds it. There is no CTO, no Head of Security, and no on-call lead to escalate to, because wrxstack is one person. That person triages it and works it directly.
The fix
Understand it, then fix it. Find the cause, ship the fix, and confirm the fix held. No paging tiers, no war room, just the work.
Telling you
Affected users hear directly. If your data or your access was affected, you get an email that says what happened and what we did. Not a status banner you have to go looking for.
02 / How one person triages

What gets dealt with first.

These are not paging tiers for a team that does not exist. They are how one person decides what to work on first when more than one thing is wrong. The order is the point, not the ceremony.

First

Data or security

Anyone's data exposed, altered, or at risk, or a confirmed security problem. This is dropped-everything work, and it triggers the notification obligation below.

Worked immediately
Next

Site or product down

Atlas, Portfolio, or the site is unavailable or badly degraded for people trying to use it. Worked next, as soon as any data or security issue is contained.

Worked once safety is clear
After

Something is off

A feature is misbehaving but the product still works and no data is at risk. Fixed in order, after the two above are clear.

Fixed in turn
Logged

Minor or cosmetic

Small glitches, wording, and rough edges. Written down and handled as part of ordinary work, not as an incident.

Handled as normal work
03 / The one obligation

The one real deadline.

Most of this page is a commitment we choose to make. This part is not optional. If personal data is breached, the law sets a clock, and we hold to it. There is no BAA, so there is no 24-hour PHI notice, because there is no PHI here to breach.

GDPR Article 33
Notify within 72 hours. If we become aware of a personal data breach, we notify within 72 hours of becoming aware, which is what the law requires of us regardless. We would rather send an incomplete notice inside 72 hours than a complete one after.
Who we tell
You, directly, by email. If your data is exposed, you get an email telling you what was accessed, when, and by whom if we know it. Not a status page update you have to find.
What we do not claim
No BAA, no HIPAA clock. We do not sign a business associate agreement, so there is no 24-hour PHI breach notice. Do not put protected health information in wrxstack.
04 / The postmortem commitment

We write down what happened.

There are no past incidents to link to here, and we are not going to pad the page with drills to make it look lived-in. When the first real one happens, this is what we will publish.

Published
Publicly, after we fix it. A postmortem on the status page with the root cause and the change we made. Not a paragraph about how seriously we take security.
Honest root cause
The actual cause. We name the change and the system that let it happen, not "an issue occurred." The target is the thing that allowed the incident, not a person.
Ends in a change
Every postmortem changes something. A code change, or a change to how the work is done, so the same thing does not recur. If nothing changed, it was not a real postmortem.
Live status
Checked from your browser. The status page checks the site, Atlas, and Portfolio in real time and reports what it observes right now. It does not store history and it does not estimate.
Trust Center · Incident response

See something broken?
Tell a human.

If you found a vulnerability, the responsible-disclosure path is below. For anything else that looks wrong, email the person who can fix it.

Responsible disclosure contact@wrxstack.comBack to Trust CenterNo on-call rotation · no incident history · one person