1. Scope
This policy covers security incidents affecting the Meridian platform and the data our customers hold in it. A security incident is any event that compromises, or credibly threatens, the confidentiality, integrity or availability of the service or of customer data.
Not every alert is an incident and not every incident is a breach of personal information. This page explains how we tell the difference and what happens in each case.
2. How we respond
Detect. Alerts, logs, customer reports and researcher reports all start the same process. Anyone at Nova System can raise an incident and we would rather investigate a false alarm than miss a real one.
Contain. The first priority is stopping the harm: isolating the affected component, revoking credentials, or taking a feature offline if that is what it takes.
Assess. We establish what happened, what data was involved, which firms are affected, and whether there is a real risk of significant harm to any individual.
Notify. See the next two sections. Notification runs in parallel with the fix, not after it.
Recover and review. We restore normal service, then write the incident up, including what we would do differently. Material lessons change the runbooks.
3. Telling our customers
Where a firm uses Meridian, that firm is the organisation accountable to its own clients, and we act on the firm behalf. So we tell the firm.
On confirmation of a personal data breach affecting a customer, we notify that customer without undue delay, as set out in the Data Processing Addendum. The notice describes what we know at the time: the nature of the incident, the categories and approximate volume of data involved, the likely consequences, the measures we have taken, and a contact point for more information.
We update the notice as the picture becomes clearer rather than waiting until we know everything. We do not publish a guaranteed notification time in hours, because a number we could not always honour would be worth less than the commitment to move as fast as the facts allow.
4. What Canadian law requires
Under the Personal Information Protection and Electronic Documents Act, an organisation must report a breach of security safeguards to the Office of the Privacy Commissioner of Canada, and notify affected individuals, as soon as feasible where the breach creates a real risk of significant harm. Records of every breach of security safeguards must be kept for twenty four months, whether or not the breach was reportable.
We keep those records. Where we are the service provider rather than the organisation holding the relationship with the individual, we support the firm in meeting its own obligations and we do not substitute our judgement for theirs.
Firms in Quebec should also read the Privacy Policy section on Law 25, which carries its own confidentiality incident register and notification duties.
5. Service disruption that is not a data incident
An outage with no data exposure is handled under the Service Availability and Support SLA documents. Incidents are posted on the Status page, and material ones are emailed to account owners.
6. Reporting something to us
Customers and clients should email security@thenovasystem.com. Security researchers should read the Responsible Disclosure Policy first.
If you believe client information has been exposed, say so in the subject line. That routes the message differently.
7. Related documents
The Security Policy describes the controls. The Business Continuity and Disaster Recovery policy covers what happens when the problem is availability rather than exposure. The Government and Law Enforcement Requests page covers demands for data.