Public summary of a draft internal runbook
Incident response
How Code Studios triages, contains, assesses and communicates security or availability incidents affecting StudioFlow.
Last updated 21 August 2026
Response process
- Record the report, preserve evidence and assign an Incident Commander, technical lead and communications owner.
- Contain continuing risk by revoking exposed credentials, isolating affected paths or pausing unsafe jobs.
- Assess affected systems, workspaces, records, people, countries, integrity and continuing risk.
- Recover in a controlled order and validate authentication, workspace separation, transactions, payments and files.
- Complete a root-cause review with corrective actions and accountable owners.
Notification
Code Studios will notify customers, controllers, regulators and affected people as required by applicable law and signed agreements. The legal/privacy lead determines the required channel and deadline from confirmed facts. We do not publish an unsupported universal notification deadline.
Readiness
The full runbook calls for an off-platform contact roster, monitored reporting inbox, preserved incident records and twice-yearly tabletop exercises. Completion and evidence of those exercises remain enterprise-readiness tasks.
Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.