Trust centre

Public summary of a draft internal runbook

Incident response

How Code Studios triages, contains, assesses and communicates security or availability incidents affecting StudioFlow.

Last updated 21 August 2026

Response process

  • Record the report, preserve evidence and assign an Incident Commander, technical lead and communications owner.
  • Contain continuing risk by revoking exposed credentials, isolating affected paths or pausing unsafe jobs.
  • Assess affected systems, workspaces, records, people, countries, integrity and continuing risk.
  • Recover in a controlled order and validate authentication, workspace separation, transactions, payments and files.
  • Complete a root-cause review with corrective actions and accountable owners.

Notification

Code Studios will notify customers, controllers, regulators and affected people as required by applicable law and signed agreements. The legal/privacy lead determines the required channel and deadline from confirmed facts. We do not publish an unsupported universal notification deadline.

Readiness

The full runbook calls for an off-platform contact roster, monitored reporting inbox, preserved incident records and twice-yearly tabletop exercises. Completion and evidence of those exercises remain enterprise-readiness tasks.

Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.