Data Leak Response
"Was customer data taken?" is the question that decides everything. We answer it properly.
A hacked website is a technical problem. Exposed customer data is a legal, financial and reputational one — with clocks already running. This service maps exactly what happened and exactly what you must do.
What we do
From "we think something leaked" to a defensible position.
Scope of exposure
Which tables, which files, which customers, which fields. Evidence-based scoping from logs and forensics — not worst-case guessing that triggers obligations you may not have.
Dark-web & paste checks
Is your data already circulating? We check leak markets, paste sites and breach corpora for your domain and datasets, and monitor for 30 days.
The regulator clock
Australian NDB (30 days to assess), GDPR (72 hours to notify), US state laws — mapped to your actual exposure, in plain English. Guidance, not legal advice; we work alongside your counsel.
Customer notification kit
Ready-to-send notification emails, a "what happened" page for your site, and internal FAQ scripts for your support team — worded to inform without inviting panic.
Credential rotation runbook
Everything that must be rotated, in order: passwords, API keys, tokens, payment webhooks — so the attacker's copied credentials become worthless.
Takedown requests
Where leaked data is posted on identifiable platforms, we file the takedowns and document the trail for your records.
Discretion
Handled quietly, documented thoroughly.
Breach work is sensitive. We practise data minimisation — we analyse what leaked, we don't warehouse it — and everything we produce is written so you could hand it to a regulator tomorrow.
Not legal advice — by design
We give you the technical facts and the regulatory map. Notification decisions belong with you and your lawyer — and the pack we produce is exactly what your lawyer will ask for anyway.