---
title: "What Happens If There Is a Security Incident?"
description: "Chatfuel has a formal incident response plan with defined roles, escalation procedures, and communication protocols."
canonical_url: https://chatfuel.com/docs/security/what-happens-if-there-is-a-security-incident
markdown_url: https://chatfuel.com/docs/security/what-happens-if-there-is-a-security-incident.md
last_updated: 2026-09-09
lang: en
site: https://chatfuel.com/docs
llms_txt: https://chatfuel.com/llms.txt
---

# What Happens If There Is a Security Incident?

Chatfuel has a formal incident response plan with defined roles, escalation procedures, and communication protocols.

## Overview [#overview]

Chatfuel has a formal incident response plan with defined roles, escalation procedures, and communication protocols. If a security incident occurs, we act quickly to contain it, notify affected parties, and prevent recurrence.

***

## Our Incident Response Process [#our-incident-response-process]

### 1. Detection [#1-detection]

Our systems run 24/7 monitoring with automated alerts. Security events are detected through:

* Continuous activity monitoring for unusual patterns
* Intrusion detection and prevention systems
* Failed login tracking and anomaly alerts
* Automated vulnerability scanning

### 2. Containment [#2-containment]

Once an incident is confirmed, our security and engineering teams immediately work to contain the threat, isolate affected systems, and prevent further impact.

### 3. Notification [#3-notification]

In the event of a confirmed data breach, affected parties are notified within **24-48 hours** in accordance with GDPR and Latin American regulatory requirements.

* **Status page** updates are published at [status.chatfuel.com](https://status.chatfuel.com)
* **Direct notification** to affected clients for security events involving their data
* **Regulatory bodies** are notified within the legally required timeframe (typically 72 hours)

### 4. Eradication and Recovery [#4-eradication-and-recovery]

We eliminate the root cause, restore affected systems, and verify that the threat has been fully resolved.

### 5. Post-Incident Review [#5-post-incident-review]

Every incident is followed by a thorough review including:

* Root cause analysis
* Corrective and preventive actions
* Reliability and security improvements
* Documentation for compliance audit trails

***

## Breach Notification by Region [#breach-notification-by-region]

| Region                     | Notification Requirement                                                        |
| -------------------------- | ------------------------------------------------------------------------------- |
| **EU (GDPR)**              | Supervisory authority within 72 hours; affected individuals without undue delay |
| **Brazil (LGPD)**          | ANPD and affected individuals within 48 hours                                   |
| **Mexico (LFPDPPP)**       | Affected individuals without undue delay                                        |
| **Colombia**               | SIC and affected individuals per regulatory guidance                            |
| **Chile, Argentina, Peru** | Per applicable local data protection law                                        |

***

## What This Means for You [#what-this-means-for-you]

* You will be notified promptly if your data is involved in any security incident
* Incident records and timelines are retained per our Data Retention & Deletion Policy
* Public incident notes never include personal or health data

***

## Contact [#contact]

If you suspect a security issue or want to report a vulnerability, contact: &#x2A;*[security@chatfuel.com](mailto:security@chatfuel.com)**

For general compliance inquiries: &#x2A;*[tos@chatfuel.com](mailto:tos@chatfuel.com)**
