Security Incident and Data Breach Policy
1. Purpose and Scope
This Security Incident and Data Breach Policy describes Spark Rack’s public commitments and general process for receiving, containing, investigating, documenting, remediating, and communicating suspected security incidents affecting Spark Rack systems or information.
- All Spark Rack Customers and prospective Customers;
- All End Users, authorized users, administrators, and account contacts;
- All Spark Rack websites, portals, control panels, networks, servers, storage systems, software, and Services;
- All resellers and downstream customers where applicable;
- All Customer Data and Customer Content processed through the Services; and
- All third-party providers used to support an applicable Service.
This public Policy does not disclose confidential technical controls, internal contacts, forensic methods, credentials, or response playbooks.
2. Definitions
2.1 Security Event
An observable occurrence that may be relevant to security but has not been confirmed as harmful.
2.2 Security Incident
A confirmed or reasonably suspected event that threatens confidentiality, integrity, availability, authentication, authorization, privacy, or lawful operation.
2.3 Data Breach
A Security Incident involving unauthorized acquisition, access, use, disclosure, alteration, loss, or destruction of protected information, as defined by applicable law.
2.4 Customer Incident
An incident primarily affecting Customer-controlled systems, applications, credentials, or Customer Content.
3. Security Is a Shared Responsibility
Spark Rack maintains reasonable administrative, technical, and physical safeguards appropriate to the Services.
No company can guarantee prevention or immediate detection of every attack, error, insider act, software defect, hardware failure, or unauthorized disclosure.
Customer remains responsible for Customer-controlled applications, credentials, access, software updates, configuration, data classification, End Users, backups, and incident response within Customer’s environment.
4. Reporting a Suspected Incident
A suspected incident should be reported promptly through the Spark Rack security or support channel.
A report should include:
- The affected Account, Service, domain, IP address, system, or user;
- The date, time, and time zone;
- A clear description of the suspected event;
- Observed indicators, errors, alerts, or unauthorized changes;
- Relevant logs or screenshots;
- Whether credentials or data may be involved;
- Actions already taken;
- Whether the incident appears ongoing;
- A reliable contact; and
- Any immediate safety, legal, or operational concern.
5. Initial Triage
Spark Rack may assess:
- Whether the event is credible;
- Whether the event is ongoing;
- Which systems and information may be affected;
- Whether Customer systems or shared infrastructure are involved;
- Whether immediate containment is required;
- Whether a third-party provider is involved;
- Whether forensic assistance is appropriate;
- Whether legal counsel should be involved;
- Whether evidence must be preserved; and
- Whether notification obligations may apply.
6. Containment Actions
Spark Rack may take immediate actions reasonably necessary to contain risk, including:
- Restricting or disabling access;
- Resetting passwords;
- Revoking sessions, tokens, keys, or certificates;
- Blocking addresses, ports, protocols, domains, or traffic;
- Isolating a server or network segment;
- Disabling a compromised feature;
- Stopping a process or Service;
- Taking a system offline;
- Preserving logs and snapshots;
- Changing routes or DNS;
- Requiring Customer action;
- Suspending an Account;
- Contacting providers or authorities; and
- Taking other protective measures.
Containment may temporarily interrupt legitimate activity.
7. Preservation of Evidence
Spark Rack may preserve relevant logs, system images, snapshots, configuration, communications, access records, and other evidence.
Personnel and Customers must not knowingly destroy, alter, conceal, or overwrite evidence after receiving a preservation instruction.
Preservation does not guarantee forensic completeness or legal admissibility.
8. Investigation
An investigation may examine:
- Initial access method;
- Affected accounts and systems;
- Malware or unauthorized tools;
- Credential use;
- Privilege escalation;
- Persistence;
- Lateral movement;
- Data access, acquisition, alteration, or deletion;
- Network activity;
- Logs and monitoring alerts;
- Provider records;
- Customer actions;
- Software vulnerabilities;
- Human error;
- Timeline and duration; and
- Containment and recovery status.
Spark Rack may engage legal counsel, forensic specialists, insurers, vendors, data centers, registrars, carriers, law enforcement, or other appropriate parties.
9. Incident Classification
Not every security alert is a Data Breach. Spark Rack may classify an event based on evidence, information type, authorization, likelihood of access, legal definitions, encryption, acquisition, risk of harm, and other circumstances.
Classification may change as new evidence becomes available.
10. Customer-Controlled Incidents
When an incident originates in Customer-controlled software, credentials, configuration, content, users, or devices, Customer is responsible for containment and remediation within that scope.
Spark Rack may assist on a best-effort or billable basis and may impose protective restrictions on affected Services.
Customer must not reconnect or restore a compromised system until reasonable remediation has occurred.
11. Third-Party Incidents
A Security Incident may involve a data center, carrier, payment processor, registrar, software provider, cloud provider, support platform, or other vendor.
Spark Rack may rely on provider information while conducting its own reasonable assessment.
Spark Rack cannot guarantee third-party investigation speed, disclosure, remediation, or evidence availability.
12. Eradication and Remediation
Remediation may include:
- Removing malicious software;
- Reinstalling systems;
- Applying patches;
- Correcting configuration;
- Rotating credentials and keys;
- Revoking unauthorized access;
- Changing firewall or network rules;
- Replacing hardware;
- Disabling vulnerable features;
- Updating monitoring;
- Restoring data;
- Rebuilding from trusted sources;
- Updating procedures;
- Training personnel; and
- Reviewing provider relationships.
No remediation can guarantee that every persistence mechanism, stolen copy, undiscovered weakness, or future attack has been eliminated.
13. Recovery and Return to Service
Spark Rack may restore systems gradually and may require validation before normal access resumes.
Recovery may include heightened monitoring, temporary restrictions, forced password resets, feature limitations, traffic filtering, backup restoration, or migration.
Service availability and data recovery remain subject to the SLA and Data Backup Policy.
14. Notification Assessment
Spark Rack will evaluate whether notification to Customers, individuals, regulators, insurers, law enforcement, or other parties is required or appropriate.
The assessment may consider applicable law, contractual roles, data type, encryption, likelihood of acquisition, risk of harm, number and location of affected persons, law-enforcement requests, and the status of the investigation.
15. Customer Notification
When legally required or otherwise appropriate, Spark Rack will provide affected Customers with information reasonably available and appropriate to the circumstances.
A notice may describe:
- The general nature of the incident;
- The date or approximate period;
- The affected Service or information categories;
- Actions Spark Rack has taken;
- Actions Customer should take;
- Available support or protective resources;
- Known limitations of the investigation; and
- A contact method for questions.
16. Timing of Notification
Notification timing depends on applicable law, investigation, containment, evidence, provider coordination, data scope, and law-enforcement restrictions.
Spark Rack will not intentionally delay a legally required notice for public-relations convenience.
Spark Rack may delay details that are unconfirmed, security-sensitive, legally restricted, or likely to impede containment or investigation.
17. Customer Responsibilities After Notice
Customer may be required to:
- Reset passwords and rotate credentials;
- Review user access;
- Preserve logs and evidence;
- Patch or rebuild Customer systems;
- Notify Customer’s End Users or regulators;
- Consult legal counsel;
- Review payment or identity information;
- Enable multifactor authentication;
- Review backups;
- Monitor for misuse;
- Provide accurate contact information; and
- Follow reasonable security instructions.
Customer is responsible for notification obligations arising from Customer’s role as controller, business, employer, merchant, covered entity, school, public body, or other regulated party.
18. Communication During an Active Incident
Spark Rack may provide updates through the Customer Portal, support tickets, email, status page, or other reasonable channels.
Updates may be delayed while personnel focus on containment, evidence preservation, recovery, or legal review.
Estimated times and preliminary causes are not guarantees and may change.
19. Confidential and Restricted Information
Spark Rack may withhold exploit details, credentials, network diagrams, detection rules, another Customer’s information, privileged advice, provider-confidential information, or facts restricted by law.
Customer must protect incident information that could facilitate further attack or expose another person.
20. Law Enforcement and Emergency Cooperation
Spark Rack may contact or cooperate with law enforcement, emergency services, regulators, child-safety organizations, or other authorities when required by law or reasonably necessary to address serious harm, crime, exploitation, or immediate danger.
Spark Rack may preserve and disclose information according to applicable law and the Law Enforcement and Legal Request Guidelines.
21. No Admission of Fault
Investigating, containing, notifying, providing assistance, or offering protective resources does not by itself constitute an admission of negligence, liability, legal violation, or contractual breach.
22. Costs and Professional Services
Spark Rack bears its own ordinary costs for incidents within Spark Rack-controlled infrastructure, subject to contracts and insurance.
Customer may be responsible for costs arising from Customer-controlled compromise, extraordinary restoration, forensic work, legal requests, malware cleanup, reinstallation, third-party charges, or repeated noncompliance when permitted by the Terms of Service.
23. Incident Records and Retention
Spark Rack may retain incident reports, logs, evidence, communications, findings, notification decisions, remediation records, and related information for security, legal, insurance, audit, fraud-prevention, and operational purposes.
Retention does not mean every raw log or data source will remain available indefinitely.
24. Lessons Learned
After a material incident, Spark Rack may review cause, detection, containment, communication, recovery, vendor performance, documentation, and corrective actions.
Spark Rack may update safeguards, training, architecture, monitoring, or policies based on the review.
25. No Absolute Security Guarantee
Spark Rack does not guarantee that every attack, compromise, unauthorized access, data loss, malware infection, insider act, software defect, or disclosure will be prevented or detected immediately.
Reasonable safeguards reduce risk but cannot eliminate all risk.
26. No AI Use
Spark Rack does not use Customer incident data, breach records, logs, evidence, or communications for AI or machine-learning training and does not authorize third parties to do so.
Automated rule-based security tools may be used for fixed signatures, thresholds, rate limits, and alerts consistent with the Artificial Intelligence Policy.
27. Contact
Suspected incidents should be reported through the security channel in the Customer Portal or published security-reporting method.
Spark RackAttn: Security Incident Response
PO Box 2215
Valdosta, GA 31604
United States
28. Acknowledgment
By using the Services, Customer acknowledges that:
- Security is a shared responsibility.
- No provider can guarantee prevention or immediate detection of every incident.
- Spark Rack may restrict or suspend Services to contain risk.
- Customer must secure Customer-controlled systems and cooperate with investigation and remediation.
- Not every Security Event is legally a Data Breach.
- Notification depends on applicable law, evidence, risk, and contractual roles.
- Spark Rack may preserve evidence and cooperate with appropriate authorities.
- Recovery may require reinstallation, credential rotation, restoration, or permanent Service changes.
- No remediation guarantees that all risk has been eliminated.