Skip to content
CyberRange
How it works AI Coach Scenarios Pricing
Request access →
Security

Incident Response & Breach Notification

This page explains, in plain terms, how EEVSEC handles a security incident or personal-data breach: how we detect it, contain it, and notify the people and regulators we’re required to. It complements our Security & Responsible Disclosure policy and our Privacy Policy. It is a summary of our commitments, not our internal runbook.

Effective: 14 June 2026 Last updated: 14 June 2026

1. How we respond

When we detect or are told about a potential incident, we follow a defined sequence: detect → triage (assess severity within a few hours) → contain (revoke access, rotate credentials, preserve evidence) → notify (regulators and affected people within the timeframes their law requires) → review (root-cause analysis and corrective actions). We keep an incident log and run a post-incident review after every confirmed incident.

2. CERT-In 6-hour reporting (India)

EEVSEC PRIVATE LIMITED is an Indian-incorporated company (CIN U62013GJ2026PTC177190) and is therefore subject to CERT-In Direction No. 20(3)/2022 (effective 27 June 2022). For in-scope cybersecurity incidents, we are committed to reporting to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of becoming aware, to incident@cert-in.org.in, in addition to any data-protection notifications below.

3. Regulatory notification timelines

Where a breach affects personal data, our notification duties depend on where the affected individuals are. The headline timelines we work to:

FrameworkWho we notifyBy when
CERT-In (India)CERT-InWithin 6 hours of awareness (in-scope incidents)
DPDPA 2023 (India)Data Protection Board of India & affected individualsPromptly, per the prescribed rules
GDPR (EU/EEA)Lead supervisory authorityWithin 72 hours of awareness, where there is a risk
GDPR (high risk)Affected individualsWithout undue delay
UK GDPRICO & affected individualsWithin 72 hours / without undue delay
UAE PDPLUAE Data Office & affected individualsWithout undue delay, per PDPL and its executive regulations
CCPA/CPRA (California)Affected residents (and the AG above 500)In the most expedient time, without unreasonable delay

If we can’t confirm full details inside a deadline, we file an initial notification and supplement it as we learn more.

4. How we’ll tell you

If an incident affects your data, we will contact you using the email associated with your account or waitlist entry, and post a notice where appropriate. Our notice will say, in plain language: what happened, what data was involved, what we’re doing about it, and what you can do to protect yourself. Enterprise customers receive notification within any tighter timeframe set in their contract or Data Processing Addendum.

5. How to report an incident to us

If you believe you’ve found a vulnerability or that an incident is in progress, please tell us right away. Follow our responsible-disclosure policy, email hi@eevsec.com with the subject “Security report”, or use the machine-readable contacts at /.well-known/security.txt. We acknowledge reports within two business days.

6. Contact

Security: hi@eevsec.com (subject: “Security report”)
Data Protection Officer: dpo@eevsec.com
EEVSEC PRIVATE LIMITED, CIN U62013GJ2026PTC177190
401, Garud Apartment, Opp: Mahabaleshwar Flat, Jodhpur Char Rasta, Ahmedabad, Gujarat 380015, India
ईवCyberRange
Live-fire cybersecurity training

Attack. Defend. Repeat.

Platform

How it works AI Coach Scenarios Doctrine Pricing Contact Newsroom Careers Academy FAQ

Company

EEVSEC EEVSEC PRIVATE LIMITED
401, Garud Apartment, Opp: Mahabaleshwar Flat,
Jodhpur Char Rasta, Ahmedabad, Gujarat 380015, India
CIN: U62013GJ2026PTC177190
hi@eevsec.com · +91 92653 59476

Legal

Privacy Policy Terms of Service Acceptable Use Refund Policy Cookie Policy Security Sitemap
© 2026 EEVSEC PRIVATE LIMITED. All rights reserved. PrivacyTermsRefundCookies