Skip to main content
Security or availability incidents are not handled ad hoc. There is a program with roles, severity criteria, containment steps, and communication rules — practiced periodically.

Response flow

1

Detect

Signals come from internal monitoring, automated alerts, or customer reports through official channels. Everything enters triage.
2

Assess

We classify impact and urgency: is there data exposure? How much of the service is affected? Who must be engaged now?
3

Contain and remediate

We limit the blast radius, remove the cause when possible, and restore operations safely — without shortcuts that reopen risk.
4

Communicate and learn

Affected parties are informed according to the nature of the event. Afterwards we record lessons and strengthen controls to reduce recurrence.

When we involve the customer

Events with material impact on confidentiality, integrity, or availability of the service are communicated through appropriate channels. Relevant operational incidents also appear on the public System Status.

How you help

Suspected unauthorized access, leaked credentials, or anomalous behavior in your account should be reported immediately to support: support@tess.im. The sooner Tess knows, the faster containment can happen in the right perimeter.