Incident Response Outline

How Letro detects, contains and resolves security incidents, and how customers are notified.

Insights That Drive Secure Communication Forward

Response Cycle

  • Detection: Monitoring of our Swiss-hosted infrastructure and reports received at [email protected].
  • Containment: Isolate affected systems; rotate infrastructure credentials and keys; suspend specific API endpoints if necessary.
  • Eradication: Patch the vulnerability; remove or rebuild any affected components.
  • Recovery: Redeploy from clean images; restore service continuity; confirm integrity of audit records.

Customer Notification

  • Severity 1 (Personal-data breach): Affected customers notified within 72 hours via email and in-app alert.
  • Severity 2 (Service degradation): Affected customers updated by email until service is restored.

Reporting a Vulnerability

Report suspected vulnerabilities to [email protected]. Our Vulnerability Disclosure Policy sets out what we ask of researchers and what you can expect from us.

How to report a security vulnerability in letro.com or the Letro applications, and what you can expect from us.

Vulnerability Disclosure Policy

Letro is encrypted and evidential. Here is how those two properties fit together.

How End-to-End Encryption and Auditability Coexist

Where Letro data lives, who operates it, and how each deployment tier changes the answer.

Data Residency & Infrastructure