Any security incident identified by our internal teams, or notified by a third party, is analyzed by our technical team — supervised by Erium's CISO and Technical Director — to confirm whether it is a genuine incident and, where applicable, to determine:
- the (affected user accounts, functionalities, data types, etc.);
- the ;
- the ;
- the ;
- the .
This information is communicated to the customers directly affected within a maximum of . The exact timing depends on the incident's severity and on whether customers need to implement security measures.