CONTAINMENT FIRST.POST-MORTEM LATER.
-
Blast radius before root cause
The first hour goes on stopping the spread: access cut, keys rotated, the reachable surface mapped. Understanding how they got in is the second hour's job.
-
Evidence, not assertions
Every line of the incident write-up carries the thing it rests on: the log entry, the request, the exploit re-run against a copy. A report is not security.
-
We know the AI attack surface
Prompt injection, agent credential theft, tool abuse, runaway spend. The failure modes we build runtimes to survive are the ones most responders have never seen.
-
You keep the machine
You finish with the detections deployed, the runbook written and the fixes merged into your repo. Not a PDF and an invoice.
Or reach us directly
If the form is not working for you, or you would rather not fill one in mid-incident, this inbox is monitored.
Reference
Incident received.
It is in front of an engineer. The first reply lands in the inbox you gave us. Keep an eye on it, and check the spam folder if nothing has arrived.
What happens next
- We read the report and come back on the contact email with what we need to start.
- You scope us the narrowest access that lets us see what is happening.
- Containment starts before anyone writes a timeline.
That did not go through.
Do not wait on this form. Send the same details to the address below and it lands in the same place.
hello@clutchsystems.ioHow we handle an active incident
- 01
Triage and containment
An engineer picks up, gets access scoped to what is needed, and works with you to stop the spread. Credentials rotated, the path in closed, the service back up on something we can watch.
- 02
Eradication and recovery
We establish how they got in and close it properly rather than papering over the symptom. Recovery runs on a path we can show is clean, not one we assume is.
- 03
Proof and hardening
Timeline, evidence and root cause written down in something you can hand to a customer or a regulator. Detections deployed, fixes merged, and the same door does not open twice.
Nothing is on fire?
Then this is the wrong form. The work we do before the incident is the cheaper half.
SEE THE SERVICES →