Incident Notification SLA
Overview
ThinkKits is committed to transparent, timely communication when security incidents affect or may affect district data or platform operations. This document defines our binding notification obligations, severity classifications, response timelines, and post-incident processes.
As a processor of publicly available education data, our incident notification program applies to all events involving unauthorized access, disclosure, or destruction of district account data, as well as service disruptions that materially affect district operations.
1. Breach Notification Timeline
ThinkKits maintains two binding notification windows from the time of confirmed incident detection:
HRS
Initial Notification — Affected Districts
Email notification to the district's designated privacy administrator and ThinkKits account contact. Includes: incident summary, data types potentially affected, immediate protective actions taken, and preliminary scope. This notification may be based on initial investigation and is subject to revision.
HRS
Detailed Incident Report — Affected Districts
Comprehensive written report to district privacy administrators. Includes: confirmed scope of affected records, root cause analysis (preliminary), full timeline of events, remediation steps completed, ongoing mitigations, and recommendations for district-side protective actions. Delivered via secure email and available in the district admin portal.
DAYS
Post-Incident Review Report
Final written review including complete root cause, all corrective actions implemented, process improvements, and confirmation of full remediation. Shared with affected districts and available upon request from any subscriber.
All timelines are measured in calendar hours from the moment ThinkKits confirms an incident has occurred. If an incident is discovered outside business hours, the clock begins at time of discovery regardless of day or time.
2. What Constitutes a Reportable Incident
ThinkKits will notify affected districts of any event meeting one or more of the following criteria:
Data Security Incidents
- Unauthorized access to, or disclosure of, district account data or platform configuration maintained by ThinkKits
- Any confirmed or suspected exfiltration of district administrator credentials or account information
- Loss or destruction of district account data that cannot be fully recovered
- Disclosure of district data to unauthorized third parties, including inadvertent disclosures
- Unauthorized modification of district-submitted data or account settings
System and Access Incidents
- Unauthorized access to district administrator accounts or privileged API credentials
- Confirmed malware, ransomware, or credential compromise affecting systems that process district data
- Exploitation of a vulnerability in ThinkKits systems that exposed district data
- Third-party sub-processor breach affecting data ThinkKits has shared under a Data Processing Agreement
Service Disruptions (P1/P2 Only)
- Platform outages exceeding 2 continuous hours affecting district access to platform data or funded procurement tools
- Data corruption events affecting district-specific datasets
Not reportable under this SLA: General platform maintenance windows (announced 72 hours in advance), performance degradation not affecting data integrity, or security events fully contained before any district data was accessed.
3. Notification Method by Severity
Email — All Incidents
Secure email to the district privacy administrator and designated ThinkKits account contact on file. Sent from security@thinkkits.com.
Includes incident ID, summary, data scope, and next steps.
Triggered: P1, P2, P3, P4
Phone Call — Critical Incidents
Direct phone call to the district's emergency contact number from ThinkKits Security team. Attempted within 2 hours of confirmed P1 incident.
If unreachable, two additional attempts are made at 30-minute intervals before falling back to email only.
Triggered: P1 (Critical) only
Admin Portal Alert
In-app notification banner visible to all district administrator accounts in the ThinkKits platform. Persists until acknowledged.
Triggered: P1, P2
Written Report
Formal PDF incident report delivered via secure email. Suitable for district records, legal review, and state reporting obligations.
Triggered: P1, P2 (within 72 hrs); P3 (within 5 days)
Districts may update emergency contact information and notification preferences at any time through the district admin portal under Settings > Security & Notifications. It is the district's responsibility to keep contact information current.
4. Incident Severity Levels
P1Critical
Confirmed unauthorized access to or exfiltration of district account data. Active exploit or breach in progress. Complete platform outage. Ransomware or destructive attack on systems holding district data.
Examples: confirmed student PII leak, active credential compromise of district admin accounts, complete data loss event
Notification: Phone + Email within 2 hours · Detailed report within 72 hours
P2High
Suspected (unconfirmed) unauthorized access to district account data. Significant service disruption affecting district data access. Vulnerability actively exploited with potential data exposure. Sub-processor breach affecting ThinkKits-shared data.
Examples: anomalous access patterns on district accounts, partial data corruption, third-party data processor incident
Notification: Email within 24 hours · Detailed report within 72 hours
P3Medium
Security event with no confirmed data exposure but requiring district awareness. Prolonged service degradation. Discovered vulnerability (not yet exploited) in systems with access to district data. Inadvertent disclosure of non-sensitive district metadata.
Examples: discovered misconfiguration (remediated), login anomaly with no confirmed breach, brief unauthorized access to non-PII data
Notification: Email within 72 hours · Summary report within 5 business days
P4Low
Minor policy violation, isolated access control issue with no data impact, or informational security finding. No student records affected. Fully contained and remediated before notification.
Examples: internal permission misconfiguration (no external access), failed attack attempt with no compromise, minor audit finding
Notification: Email within 5 business days (summary only)
5. Response SLAs by Severity
| Severity | Initial Response | District Notification | Detailed Report | Containment Target | Resolution Target |
|---|---|---|---|---|---|
| P1 Critical | 15 minutes | 2 hours (phone + email) | 72 hours | 4 hours | 24 hours |
| P2 High | 30 minutes | 24 hours (email) | 72 hours | 8 hours | 48 hours |
| P3 Medium | 2 hours | 72 hours (email) | 5 business days | 24 hours | 5 business days |
| P4 Low | 1 business day | 5 business days (email) | On request | 5 business days | 30 days |
All times are measured from confirmed detection. "Initial Response" means internal incident response team is engaged and investigation begins. "Containment" means the threat vector is neutralized and no further unauthorized access is possible. "Resolution" means all affected systems are restored and remediation is complete.
ThinkKits maintains 24/7/365 on-call security coverage for P1 and P2 incidents. Response SLAs apply at all hours including weekends and holidays.
6. Post-Incident Review Process
All P1 and P2 incidents trigger a mandatory post-incident review. P3 incidents are reviewed at ThinkKits' discretion. P4 incidents are tracked internally and included in quarterly security reports.
Incident Closure Confirmation
- Confirm all affected systems restored to normal operation
- Verify no residual unauthorized access exists
- Notify affected districts of incident closure
- Preserve all logs and forensic artifacts for review
Internal Review (Blameless Post-Mortem)
- Timeline reconstruction: what happened and when
- Root cause analysis: technical and process failures identified
- Detection gap analysis: why was detection delayed (if applicable)
- Response effectiveness review: what worked, what did not
- Corrective action items assigned with owners and deadlines
District Report Delivery
- Final incident report delivered to all affected districts
- Includes: confirmed scope, root cause, full corrective action plan
- Confirmation that all remediation steps have been completed
- Recommendations for any district-side protective actions
- Available in PDF format for district records and state reporting
Corrective Action Verification
- Independent verification that all corrective actions are implemented
- Updated control testing where applicable
- Lessons learned incorporated into security training and runbooks
- Summary available to districts upon request
Quarterly Aggregate Reporting
- Aggregate incident counts and category breakdowns (no district-identifying data)
- Trend analysis and year-over-year comparison
- Published in the ThinkKits Trust Center and emailed to district admins
7. Data Privacy Obligations
As a processor of publicly available education data, ThinkKits does not access, store, or process student education records as defined under FERPA. ThinkKits is not a "school official" under FERPA. Accordingly:
- Data scope: ThinkKits processes only publicly available NCES school-level data. No student-level personally identifiable information enters our systems.
- District notification obligation: When required by applicable state law, ThinkKits will provide districts with all information necessary to fulfill their own notification obligations.
- Regulator cooperation: In the event of a data breach, ThinkKits will cooperate fully with applicable regulators and provide all requested documentation within 10 business days of request.
- State law compliance: Where state data privacy laws impose stricter notification timelines than this SLA (e.g., Colorado, California, New York), ThinkKits will meet the more stringent requirement.
- District support: ThinkKits will provide districts with draft notification language and a dedicated support contact for inquiries resulting from a breach notification.
8. District Responsibilities
Effective incident response requires cooperation from district stakeholders. Districts are responsible for:
- Maintaining current emergency contact information in the ThinkKits admin portal
- Designating a privacy administrator who has authority to receive breach notifications
- Responding to ThinkKits information requests during active incident investigations within 4 hours for P1 incidents
- Notifying ThinkKits promptly if district-side credentials or API keys are suspected compromised
- Fulfilling any independent notification obligations to parents, students, or state agencies under applicable law
Security Contact
To report a suspected incident, request an incident report, or ask questions about this policy:
Email: security@thinkkits.com
Response time: Within 1 hour for active incidents · Within 1 business day for general inquiries
For active P1 incidents, email security@thinkkits.com with subject line "P1 INCIDENT" to trigger immediate on-call escalation.
Related Policies
- Incident Response Plan — Internal procedures and technical response playbooks
- FERPA Compliance — Full FERPA compliance documentation
- Sub-Processors — Third-party processors with access to district data
- Data Retention Policy — How long district data is retained and deletion procedures
- Service Level Agreement — Platform uptime and availability commitments
- Trust Center — Full security and compliance overview