ConveYour maintains a process for responding to incidents involving security, privacy, reliability, or AI-enabled features. The purpose is to identify and contain harm, investigate what happened, restore safe operation, address the underlying cause, and communicate with affected customers when appropriate.
An incident may involve a security event, unauthorized access, improper data handling, material service disruption, inaccurate or harmful AI output, suspected bias, misuse, or a failure of a third-party provider.
ConveYour encourages employees, contractors, customers, and relevant providers to report suspected incidents promptly through established support or security channels.
Reports should include the information available at the time, such as the feature involved, affected workflow, approximate timing, observed behavior, data or individuals potentially affected, and any immediate steps already taken.
ConveYour treats good-faith reports seriously. A report does not need to prove that an incident occurred before it is reviewed.
ConveYour assesses reported incidents based on their severity, scope, likelihood of harm, affected data or individuals, customer impact, and legal or contractual implications.
Higher-priority incidents may include suspected unauthorized disclosure of sensitive data, a material defect in an employment-related workflow, sustained service disruption, evidence of harmful or discriminatory output, or a provider event that materially affects customers.
The incident owner coordinates the response and brings in the relevant product, security, privacy, customer-support, legal, or provider contacts as needed.
ConveYour takes reasonable steps to contain a suspected incident while it investigates. Depending on the situation, the company may restrict access, disable a workflow, pause an AI-enabled feature, revoke credentials, limit data flows, preserve records, or work with a provider to address the issue.
The investigation may review relevant audit records, feature configuration, model or prompt versions, system events, customer reports, access activity, provider information, and test history.
ConveYour documents material findings, decisions, and actions taken.
After confirming an issue, ConveYour determines corrective actions proportionate to the risk. Remediation may include: