Incident Response & Breach Notification
Effective Date: March 30, 2026
MultiMFA, Inc. ("MultiMFA", "we", "us") operates the MultiMFA platform with a focus on reliability and transparency. This page describes how we prepare for, respond to, and communicate about security incidents and personal data breaches, so you know what to expect if something goes wrong.
1. Purpose and scope
This policy applies to incidents affecting the confidentiality, integrity, or availability of MultiMFA services or customer data that we process on your behalf. It complements our Privacy Policy, Terms of Service, and Security overview. It is not a substitute for legal advice; where laws impose specific duties, we follow those requirements.
2. Service operation and subprocessors
We operate the MultiMFA platform using security practices appropriate to our risk and scale. We intentionally do not publish detailed architecture, hosting vendors, or internal topology on this page—doing so would add little customer value and can assist attackers. We rely on essential subprocessors (for example for SMS delivery and payment processing) whose availability and security can affect the service; incidents involving those providers may require coordinated response on our side.
3. Reporting a security issue
If you discover a vulnerability, suspected unauthorized access, or abuse related to MultiMFA, please contact us promptly:
- Email: [email protected] with the subject line starting with Security(for example: "Security — suspected account access").
- In-app: Use the support option on the site so your report is tracked with your account when relevant.
Please include enough detail for us to reproduce or investigate (steps, time window, affected accounts or numbers if known). We appreciate responsible disclosure and will not retaliate against good-faith research that avoids harm to users or the service.
4. Our incident response process
When we become aware of a potential security incident, we generally take the following steps:
- Triage and ownership. We assign responsibility, record what we know, and classify severity (for example: service degradation vs. suspected data exposure).
- Containment. We act to limit ongoing harm—for example by restricting access, rotating credentials, blocking abusive traffic, or temporarily limiting functionality if needed.
- Investigation. We analyze available evidence and relevant status information to determine root cause and scope. We preserve material evidence where appropriate.
- Recovery. We restore normal operation safely, validate integrity, and monitor for recurrence.
- Follow-up. We document lessons learned and implement changes to reduce similar risk (patching, monitoring, process updates).
We aim to respond to good-faith security reports without undue delay. Initial triage often begins within one business day for reports sent to the contact above; severity and staffing may shorten or extend that window. We cannot guarantee a specific fix timeline for every issue, but we treat credible reports seriously.
5. Personal data breaches and notification
A personal data breach means an incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data we process in connection with the service. Not every security incident is a personal data breach (for example, a denial-of-service that does not expose data).
If we determine that a breach has occurred and is likely to affect your personal data:
- We will notify affected users when required by applicable law or when we reasonably believe notification is appropriate to help you protect yourself. Notification may be by email to the address on your account or by a prominent notice on the service.
- We will describe, to the extent we can determine at the time, what happened in general terms, categories of data involved, what we are doing, and steps you may take (such as rotating passwords or reviewing connected accounts).
- Where the law requires notifying regulators or other parties, we will do so within the timeframes those laws require, which vary by jurisdiction and facts.
Because MultiMFA is designed to minimize sensitive data exposure (for example, SMS content is typically short-lived verification traffic), many incidents have limited impact on identifiable personal data. We still assess each case on its merits.
6. Service availability and communication
Operational issues (including dependency or hosting outages) may be communicated through support channels, email, or on-site notices. We work to restore service and to be transparent about widespread outages that materially affect access to your account.
7. Changes to this policy
We may update this page to reflect process improvements or legal requirements. The "Effective Date" at the top will change when we do. For material changes, we will provide additional notice where appropriate (for example, email or dashboard notice). Continued use of the service after updates constitutes acceptance of the revised policy where permitted by law.
8. Contact
Questions about this policy: [email protected].
Related: Privacy Policy · Acceptable Use Policy · Security details · Service Level (SLA)