Incident Response Plan

Charming Holdings LLC · Reviewed and updated: May 17, 2026 · Next review due: November 17, 2026 (every 6 months)

This document describes how Charming Holdings LLC ("the company") responds to a security incident affecting buyer data, system integrity, or operational availability. It is reviewed every six months and any time there is a material change in our systems or personnel.

Scope

This plan applies to any incident involving data received from a marketplace (Amazon, Walmart, eBay), the systems that process that data (our application server, database, and supporting infrastructure), or the accounts that access them.

Roles

RolePersonContact
Incident Management Point of Contact (IMPOC)Betzalel Bree[email protected]
Backup IMPOCSame individual; secondary contact via SMS to the listed phone if email unreachable+1 (732) 395-7331

Because this is a small operation, the IMPOC is also the individual who executes containment and remediation steps. If that person is unavailable, the IRP is paused until they are reachable; this is documented as an operational risk.

Severity classification

SeverityExamplesTriage SLA
CriticalConfirmed PII data leak, active intrusion, ransomwareWithin 30 minutes
HighSuspected unauthorized access, leaked credential, exposed API keyWithin 1 hour
MediumVulnerability with no confirmed exploitation, unusual access patternWithin 4 hours
LowFailed-login bursts, security patch neededWithin 1 business day

Response steps

1. Detect

Incidents are surfaced through:

2. Triage

The IMPOC classifies severity using the table above within the listed SLA and opens an incident record (private GitHub issue with severity label and timestamps).

3. Contain

4. Notify (within 24 hours of detection)

For incidents involving marketplace data, the IMPOC notifies the affected marketplace's security contact within 24 hours of detection, with: incident summary, time of detection, approximate scope of affected data, containment actions taken, and next-step plan.

MarketplaceContact
Amazon[email protected]
WalmartWalmart Marketplace Seller Center vulnerability reporting
eBayeBay Security Vulnerability Reporting program

If the incident also triggers a regulatory notification obligation (e.g., state breach notification laws), the IMPOC executes that notification per the applicable law.

5. Investigate

6. Eradicate

7. Recover

8. Lessons learned (within 7 days)

Plan review cadence

This IRP is reviewed every 6 months by the IMPOC. Each review confirms: contact information is current, marketplace security contacts are current, severity examples still reflect realistic threats to our environment, and the post-incident lessons from the prior period have been incorporated. Reviews are logged in our private GitHub repository.