LONNA by Alphabridge

← All legal pages

Security Compromise Procedure

DRAFT, version 2026-10 draft 1. This text has not been approved by an attorney yet. Items in [square brackets] are still to be filled in.

What Alphabridge does if personal information in LONNA may have been accessed by someone who should not have seen it (POPIA sections 21 and 22). Internal procedure; summary published for customers.

1. Spot and contain (immediately)

Anyone who suspects a compromise tells the Information Officer at once: [name, phone, e-mail]. Contain it: deactivate the affected users, suspend the affected account if needed, and change the system secret key (this signs everybody out). Do not delete anything; keep the audit trail and logs.

2. Assess (the same day)

Find out what happened, when, which customers and which information are involved, and whether it is still going on. Use the audit trail and the support-access records. Write down the findings with times.

3. Tell the customers (without delay, within [24] hours of knowing)

Alphabridge is the operator for payroll information: tell each affected customer's account owner what is known (what, when, which information, what we are doing). The customer, as responsible party, decides about informing the Information Regulator and the data subjects, and we help it do so as soon as reasonably possible.

For information where Alphabridge is the responsible party (account and billing details), Alphabridge notifies the Information Regulator and the people concerned as soon as reasonably possible after discovery, in the way the Regulator prescribes.

4. Fix

Close the gap, change passwords and keys that may be exposed, restore from a clean backup if needed, and check that it is fixed.

5. Record and learn

Keep a written record of the incident, the decisions and the notices. Within [14] days review what went wrong and what will change. Update this procedure.