Back
Security
Natty Hatty — Incident Response Policy
Version: v1.0
Effective Date: November 15, 2025
Natty Hatty maintains a formal Incident Response Policy designed to detect, investigate, contain, and resolve security incidents quickly and effectively. Because we process sensitive youth sports data, signatures, and minors’ information, our incident response processes prioritize speed, clarity, security, and transparency.
This is a high-level public summary of our internal policy.
1. Purpose of the Incident Response Policy
The purpose of this policy is to:
Protect the confidentiality, integrity, and availability of Natty Hatty systems and data
Respond rapidly to security incidents
Minimize disruption to customers, coaches, parents, and minors
Prevent recurrence of similar incidents
Comply with all applicable laws and regulations (e.g., COPPA, CPRA, ESIGN, UETA)
Maintain trust with our customers and partners
2. What Constitutes a Security Incident
A “Security Incident” includes, but is not limited to:
Unauthorized access to user accounts or organizational accounts
Attempts to bypass authentication or security controls
Data exposure, leakage, or suspected breach
Compromise of session tokens or API credentials
Malware, phishing, or targeted attacks impacting Natty Hatty systems
Integrity issues with signed documents, audit logs, or e-signature hashes
DDoS or service-disruption attempts
Misuse or unauthorized access of minors’ data
Unauthorized access by internal personnel (rare but monitored)
Natty Hatty treats any incident involving children’s data as high severity.
3. Incident Response Lifecycle
Natty Hatty follows a structured, industry-standard lifecycle:
3.1 Identification
We employ continuous monitoring tools to detect anomalies using:
AWS CloudWatch
AWS GuardDuty
AWS WAF alerts
Internal logging and anomaly detection
Authentication anomaly alerts (device/IP mismatch)
Customer reports
Once identified, the Security Team classifies the incident severity.
3.2 Containment
Depending on severity, containment actions may include:
Revoking access tokens and logouts across devices
Temporarily freezing affected accounts
Blocking suspicious IPs or regions
Isolating compromised systems
Pausing specific API endpoints
Locking signature workflows if audit integrity may be impacted
Applying firewall or WAF filters
Critical incidents are contained within minutes of confirmation.
3.3 Investigation
The Security Team conducts a structured investigation:
Reviewing logs, access trails, and timestamps
Analyzing device and IP signatures
Verifying integrity of audit trails and signature hashes
Determining the origin, vector, and scope of compromise
Assessing any exposure to minors’ data
Evaluating impact on customer organizations
Documenting findings in a security report
Third-party forensic teams may be engaged for major incidents.
3.4 Eradication & Remediation
Once root cause is determined, we:
Patch or update vulnerable systems
Reset internal and external keys where needed
Revoke compromised credentials
Apply hardened configurations
Address misconfigurations
Improve detection rules
Strengthen audit trails or session logic
All remediation steps are logged and reviewed.
3.5 Recovery
Systems are carefully restored to full operation, including:
Validating integrity of core services (login, payments, signatures)
Ensuring signed documents and audit trails remain tamper-proof
Verifying no persistence mechanisms remain
Monitoring systems closely after restoration
Communicating with affected customers as needed
3.6 Post-Incident Review (PIR)
Following resolution, Natty Hatty performs a formal internal review:
Detailed analysis of incident timeline
What worked and what needs improvement
Additional security investments required
Policy revisions
Updates to detection rules
Employee training refreshers
Learnings are integrated into ongoing security enhancement initiatives.
4. Notification to Customers
If an incident involves personal information, minors’ information, or signed documents, Natty Hatty will:
Notify affected customers as required by law
Provide details on what occurred and what data was impacted
Explain the remediation steps taken
Provide guidance on protective actions (if applicable)
Communicate transparently and promptly
We comply with California CPRA, COPPA, and other state breach-notification laws.
5. Protection of Minors’ Data During Incidents
Because Natty Hatty supports youth sports and handles minors’ information:
Incidents involving children’s data automatically trigger highest-priority escalation
Investigation must begin immediately
Parental/guardian notification is coordinated through the organization when appropriate
Additional verification steps are taken during customer re-authentication
Natty Hatty maintains a zero-tolerance stance regarding misuse of minors’ information.
6. Roles & Responsibilities
Security Team
Leads detection, investigation, remediation, and communication
Engineering Team
Implements fixes, restores systems, reviews code integrity
Compliance & Legal Team
Determines notification obligations
Ensures compliance with COPPA, CPRA, ESIGN, UETA, etc.
Executive Team
Oversees high-severity incidents
Approves major communications or platform changes
Support Team
Interfaces with impacted customers
Provides ongoing updates
7. Law Enforcement & Third-Party Coordination
Natty Hatty may engage:
Local law enforcement
State or federal cybercrime units
Third-party penetration testers
AWS support and security specialists
We only share information when legally required or necessary to protect users.
8. Continuous Improvement
Natty Hatty reviews and updates its Incident Response Policy regularly to account for:
Emerging threats
New AWS capabilities
Platform updates
Regulatory changes
Industry standards (OWASP, NIST)
We aim for constant improvement in preparedness and response.
9. Reporting Security Issues
We encourage responsible disclosure.
Email security concerns to: