Security Incident Response Policy

Last Updated: February 11, 2026 · App: Smart Que · Company: IObits Technologies

1. Purpose

This Security Incident Response Policy describes how Smart Que, operated by IObits Technologies, detects, responds to, manages, and reports security incidents affecting personal data or system infrastructure.

2. Scope

This policy applies to:

  • Shopify store data accessed via API
  • Customer and order data processed by Smart Que
  • Backend servers and databases
  • Cloud hosting infrastructure
  • Application logs and backups

3. Definition of Security Incident

A security incident includes:

  • Unauthorized access to personal data
  • Data breach or data exposure
  • Compromised credentials
  • Infrastructure compromise
  • Service disruption due to malicious activity

4. Detection

Security incidents may be identified through:

  • System monitoring and logging
  • Cloud security alerts
  • Merchant reports
  • Internal review

5. Response Procedure

Containment

  • Restrict access to affected systems
  • Rotate credentials and API keys
  • Isolate impacted infrastructure

Investigation

  • Assess scope and impact
  • Identify affected data
  • Review logs and access history

Mitigation

  • Patch vulnerabilities
  • Restore systems from secure backups
  • Strengthen access controls

6. Notification

If a confirmed security incident involves personal data:

  • Affected merchants will be notified without undue delay
  • Shopify will be notified if required under Shopify Partner terms
  • Notifications will include incident details and recommended actions

7. Recovery & Improvement

Following resolution, we will:

  • Verify system integrity
  • Monitor for recurring threats
  • Improve preventive controls

8. Preventive Safeguards

Smart Que implements:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest and encrypted backups
  • Role-based access control
  • Separation of environments
  • Limited internal staff access

9. Contact

Security concerns can be reported to:

Company: IObits Technologies
Email: iobitstechnologies1122@gmail.com