Incident Response Policy
How we detect, contain, and communicate security or data incidents — and our commitment to transparency.
Purpose
This Incident Response Policy describes how Home Base Appraisal Management Company, LC (“Home Base AMC”) identifies, classifies, responds to, and communicates security incidents or data breaches that may affect our clients, appraisers, or platform users.
Incident Classification
Active breach, data exfiltration, or complete service outage affecting clients.
Partial service disruption, suspected unauthorized access, or potential data exposure.
Isolated technical errors, policy violations, or low-risk anomalies with no data exposure.
Response Procedures
Detection & Identification
Incidents are detected via automated monitoring, developer alerts, or reports from staff or clients. All reports are triaged within 1 hour during business hours.
Containment
The affected system or data pathway is immediately isolated. For critical incidents, our on-call development team engages to contain the issue.
Assessment
We determine the scope and nature of the incident: what data was involved, who was affected, and the root cause.
Notification
Affected clients and, where required by law, regulators are notified within 72 hours of a confirmed breach. We do not delay notification to complete internal remediation.
Remediation
Root cause is addressed, security patches deployed, and controls updated. A post-incident review is completed within 5 business days.
Documentation
All incidents are documented in our incident register. Critical incidents are included in our annual SOC 2 audit review.
Report an Incident
If you believe you have discovered a security vulnerability or have experienced a potential breach related to our platform, please contact us immediately:
Security Contact
Contact us via our contact form (select “Compliance / vendor management”) or call us directly.
Phone (urgent): (801) 449-9200
Regulatory Compliance
Our incident response procedures are designed to comply with applicable federal and state regulations, including Gramm-Leach-Bliley Act (GLBA) safeguard requirements, state data breach notification laws, and our SOC 2 (SSAE 18) audit obligations.
