How we detect, contain and notify security incidents, and the service commitments behind ConsentX. Factual, with no certification we have not earned.
1. Detect & triage
Monitoring and alerting surface anomalies. On report or alert, we triage severity and scope and open an incident with an owner.
2. Contain
We isolate affected systems, revoke or rotate credentials as needed, and stop the spread before moving to eradication.
3. Notify
For a personal data breach we notify affected customers without undue delay and within 48 hours of becoming aware, per our DPA, and support notification to the Data Protection Board and affected data principals under the DPDPA.
4. Eradicate & recover
We remove the root cause, restore from encrypted backups where needed, and verify integrity before returning to normal operations.
5. Post-incident review
Every significant incident gets a written review with root cause and corrective actions, fed back into controls and monitoring.
TLS in transit; storage-layer encryption at rest on AWS, including encrypted backups.
Least-privilege access with MFA on production; Cloudflare WAF and DDoS mitigation at the edge.
Application and consent data hosted on AWS in Mumbai (ap-south-1), India, with intra-region processing by default.
Consent events are sealed in a SHA-256 hash chain, so records are tamper-evident and verifiable.
ConsentX operates to a 99.9% uptime target, measured monthly. A contractual uptime SLA with service credits is available on the Enterprise plan: contact sales for the current SLA schedule.
In the event of a ConsentX outage, the consent widget is designed to fail open, so your site's cookie banner does not block page rendering or checkout flows.
Found a security issue? Email privacy@consentx.io. We acknowledge valid reports and work with researchers to resolve them.