Back to OMEGA
Legal
Incident Response and Recovery
How OMEGA classifies, responds to, and communicates incidents affecting Central and support systems.
Effective: July 8, 2026Last updated: July 8, 2026
Summary
Because OMEGA is a native local-first app, most customer work product lives on the customer’s Mac. Incident response focuses on Central entitlement, billing, website, update, account, support, and optional diagnostics infrastructure.
Severity
- Critical: confirmed unauthorized access to Central account/license data, active exploitation, payment integrity issue, update distribution compromise, or signing-key compromise.
- High: material vulnerability with realistic abuse path, outage preventing paid users from activating, or support/diagnostics data exposure.
- Medium: limited exploitability, isolated availability issue, or security control degradation.
- Low: defense-in-depth gap, documentation error, or low-risk misconfiguration.
Response Runbook
- Triage: confirm report, preserve logs, assign severity, identify affected systems, and stop unsafe automation if needed.
- Contain: rotate credentials, disable vulnerable routes, block malicious traffic, pause affected releases, or revoke suspect device/session tokens.
- Eradicate: patch root cause, add regression tests, verify database state, and confirm no secondary footholds remain.
- Recover: restore service, verify entitlement/billing correctness, re-enable affected automation, and monitor for recurrence.
- Postmortem: document timeline, customer impact, root cause, corrective actions, and owner/date for each action.
Backup and Restore
- Central database snapshots are encrypted and access-controlled.
- Restore procedure must verify schema compatibility, legal acceptance records, Stripe event dedupe records, license audit history, and entitlement correctness before traffic is restored.
- Local customer OMEGA data is not backed up by Central. Users are responsible for backing up their Mac unless they use an OMEGA-supported export/backup feature.
- Recovery testing must include account login, license validation, device activation/deactivation, checkout status, and legal evidence retrieval.
Notification
OMEGA will notify affected users when required by law or when an incident creates a material risk to account, billing, device, entitlement, support, diagnostics, or update integrity. Security notices are sent to the account email and may also be posted on the Security or Status page.