← Trust Center

Incident Notification SLA

Last updated: March 2026 · Version 1.0 · Classification: Public · Applies to: All ThinkKits districts and institutional subscribers

Compliance Notice: ThinkKits processes only publicly available education data and does not access, store, or process student education records as defined under FERPA. Our incident notification procedures are designed to meet applicable state data privacy laws and industry best practices for data security.

Overview

ThinkKits is committed to transparent, timely communication when security incidents affect or may affect district data or platform operations. This document defines our binding notification obligations, severity classifications, response timelines, and post-incident processes.

As a processor of publicly available education data, our incident notification program applies to all events involving unauthorized access, disclosure, or destruction of district account data, as well as service disruptions that materially affect district operations.

1. Breach Notification Timeline

ThinkKits maintains two binding notification windows from the time of confirmed incident detection:

24
HRS

Initial Notification — Affected Districts

Email notification to the district's designated privacy administrator and ThinkKits account contact. Includes: incident summary, data types potentially affected, immediate protective actions taken, and preliminary scope. This notification may be based on initial investigation and is subject to revision.

72
HRS

Detailed Incident Report — Affected Districts

Comprehensive written report to district privacy administrators. Includes: confirmed scope of affected records, root cause analysis (preliminary), full timeline of events, remediation steps completed, ongoing mitigations, and recommendations for district-side protective actions. Delivered via secure email and available in the district admin portal.

30
DAYS

Post-Incident Review Report

Final written review including complete root cause, all corrective actions implemented, process improvements, and confirmation of full remediation. Shared with affected districts and available upon request from any subscriber.

All timelines are measured in calendar hours from the moment ThinkKits confirms an incident has occurred. If an incident is discovered outside business hours, the clock begins at time of discovery regardless of day or time.

2. What Constitutes a Reportable Incident

ThinkKits will notify affected districts of any event meeting one or more of the following criteria:

Data Security Incidents

System and Access Incidents

Service Disruptions (P1/P2 Only)

Not reportable under this SLA: General platform maintenance windows (announced 72 hours in advance), performance degradation not affecting data integrity, or security events fully contained before any district data was accessed.

3. Notification Method by Severity

Email — All Incidents

Secure email to the district privacy administrator and designated ThinkKits account contact on file. Sent from security@thinkkits.com.

Includes incident ID, summary, data scope, and next steps.

Triggered: P1, P2, P3, P4

Phone Call — Critical Incidents

Direct phone call to the district's emergency contact number from ThinkKits Security team. Attempted within 2 hours of confirmed P1 incident.

If unreachable, two additional attempts are made at 30-minute intervals before falling back to email only.

Triggered: P1 (Critical) only

Admin Portal Alert

In-app notification banner visible to all district administrator accounts in the ThinkKits platform. Persists until acknowledged.

Triggered: P1, P2

Written Report

Formal PDF incident report delivered via secure email. Suitable for district records, legal review, and state reporting obligations.

Triggered: P1, P2 (within 72 hrs); P3 (within 5 days)

Districts may update emergency contact information and notification preferences at any time through the district admin portal under Settings > Security & Notifications. It is the district's responsibility to keep contact information current.

4. Incident Severity Levels

P1Critical

Confirmed unauthorized access to or exfiltration of district account data. Active exploit or breach in progress. Complete platform outage. Ransomware or destructive attack on systems holding district data.

Examples: confirmed student PII leak, active credential compromise of district admin accounts, complete data loss event

Notification: Phone + Email within 2 hours · Detailed report within 72 hours

P2High

Suspected (unconfirmed) unauthorized access to district account data. Significant service disruption affecting district data access. Vulnerability actively exploited with potential data exposure. Sub-processor breach affecting ThinkKits-shared data.

Examples: anomalous access patterns on district accounts, partial data corruption, third-party data processor incident

Notification: Email within 24 hours · Detailed report within 72 hours

P3Medium

Security event with no confirmed data exposure but requiring district awareness. Prolonged service degradation. Discovered vulnerability (not yet exploited) in systems with access to district data. Inadvertent disclosure of non-sensitive district metadata.

Examples: discovered misconfiguration (remediated), login anomaly with no confirmed breach, brief unauthorized access to non-PII data

Notification: Email within 72 hours · Summary report within 5 business days

P4Low

Minor policy violation, isolated access control issue with no data impact, or informational security finding. No student records affected. Fully contained and remediated before notification.

Examples: internal permission misconfiguration (no external access), failed attack attempt with no compromise, minor audit finding

Notification: Email within 5 business days (summary only)

5. Response SLAs by Severity

Severity Initial Response District Notification Detailed Report Containment Target Resolution Target
P1 Critical 15 minutes 2 hours (phone + email) 72 hours 4 hours 24 hours
P2 High 30 minutes 24 hours (email) 72 hours 8 hours 48 hours
P3 Medium 2 hours 72 hours (email) 5 business days 24 hours 5 business days
P4 Low 1 business day 5 business days (email) On request 5 business days 30 days

All times are measured from confirmed detection. "Initial Response" means internal incident response team is engaged and investigation begins. "Containment" means the threat vector is neutralized and no further unauthorized access is possible. "Resolution" means all affected systems are restored and remediation is complete.

ThinkKits maintains 24/7/365 on-call security coverage for P1 and P2 incidents. Response SLAs apply at all hours including weekends and holidays.

6. Post-Incident Review Process

All P1 and P2 incidents trigger a mandatory post-incident review. P3 incidents are reviewed at ThinkKits' discretion. P4 incidents are tracked internally and included in quarterly security reports.

1

Incident Closure Confirmation

Within 24–48 hours of resolution
  • Confirm all affected systems restored to normal operation
  • Verify no residual unauthorized access exists
  • Notify affected districts of incident closure
  • Preserve all logs and forensic artifacts for review
2

Internal Review (Blameless Post-Mortem)

Within 5 business days of resolution
  • Timeline reconstruction: what happened and when
  • Root cause analysis: technical and process failures identified
  • Detection gap analysis: why was detection delayed (if applicable)
  • Response effectiveness review: what worked, what did not
  • Corrective action items assigned with owners and deadlines
3

District Report Delivery

Within 30 days of resolution
  • Final incident report delivered to all affected districts
  • Includes: confirmed scope, root cause, full corrective action plan
  • Confirmation that all remediation steps have been completed
  • Recommendations for any district-side protective actions
  • Available in PDF format for district records and state reporting
4

Corrective Action Verification

30–90 days post-incident
  • Independent verification that all corrective actions are implemented
  • Updated control testing where applicable
  • Lessons learned incorporated into security training and runbooks
  • Summary available to districts upon request
5

Quarterly Aggregate Reporting

Ongoing — all subscriber tiers
  • Aggregate incident counts and category breakdowns (no district-identifying data)
  • Trend analysis and year-over-year comparison
  • Published in the ThinkKits Trust Center and emailed to district admins

7. Data Privacy Obligations

As a processor of publicly available education data, ThinkKits does not access, store, or process student education records as defined under FERPA. ThinkKits is not a "school official" under FERPA. Accordingly:

8. District Responsibilities

Effective incident response requires cooperation from district stakeholders. Districts are responsible for:

Security Contact

To report a suspected incident, request an incident report, or ask questions about this policy:

Email: security@thinkkits.com

Response time: Within 1 hour for active incidents · Within 1 business day for general inquiries

For active P1 incidents, email security@thinkkits.com with subject line "P1 INCIDENT" to trigger immediate on-call escalation.

Related Policies

Was this article helpful?

← Back to Help Center