Companies that don't publish incident histories usually have incidents. Companies that do publish them almost always have fewer, because writing 'we had an incident' publicly is a cost that surfaces the operational discipline needed to avoid the next one.
Current state
Zero material security incidents since launch. This is a real zero, not a rounded-down one. If we experienced an incident that affected customer data, connectivity, or the integrity of our service, it would appear on this page within 72 hours of confirmed detection.
What counts as a material incident
- Any unauthorized access to customer data (chats, files, account records).
- Any credential exposure affecting LADLE staff or customers.
- Any confirmed data leak from LADLE or one of our subprocessors that affected LADLE data.
- Any prolonged service degradation caused by a security decision (e.g., taking a system offline to contain a suspected breach).
- Any regulatory notification we made about a suspected privacy incident.
What doesn't count
- Blocked attacks (WAF-blocked exploits, failed brute-force attempts, DDoS mitigations that succeeded). These are logged internally but not published — they'd be a firehose that hides real signal.
- Vulnerability reports from researchers where no exploitation occurred; those land on /security/vulnerability-disclosure with credit.
- Third-party incidents at our subprocessors that didn't affect LADLE data (still noted internally, but published only if LADLE data was involved).
If an incident happens
- 0-24h: Detection, containment, initial customer notification via email + /status.
- 24-72h: Public entry appears on this page. GDPR-mandated regulatory notification within 72h where applicable.
- 7 days: Interim update — what we've learned, what's still unknown.
- 30 days: Full post-mortem with root cause, remediation, and prevention measures published under the incident entry.
Related
/security — overall posture. /security/vulnerability-disclosure — how to report a vulnerability. /status — real-time service status (separate from security incidents).
REPORT AN INCIDENT · PRIVACY@LADLE.CHAT