MoniSa Enterprise PortalReturn to sign in
Portal governance

Report a Security or Privacy Incident

A safe route to report lost access, exposed data, suspicious activity or a portal vulnerability.

Version 2.0Effective 19 August 2026Owner: Portal & Data Governance

1. Report within four hours

Report any suspected security or personal-data incident to security@monisaenterprise.com within four hours of discovery and provide the fuller written report within 24 hours. For a privacy grievance that is not an urgent incident, use grievance@monisaenterprise.com.

Include the affected page or account, date/time and time zone, what you observed, whether project or personal data may be involved, and a safe way to contact you. Do not send passwords, authentication tokens, full identity documents or client files in the first email.

2. Preserve, contain and coordinate notifications

Stop the affected action if safe, revoke exposed access within four hours, sign out of compromised sessions, change the password from a trusted device, preserve relevant timestamps or screenshots, and do not delete evidence. Answer urgent incident questions within four hours and report within four hours if an affected participant may be under 18. Coordinate external communications with MoniSa. Nothing here prohibits or penalises a statutory or regulatory report, supervisory-authority complaint, protected disclosure, request for legal advice, or preservation or production of evidence where the law protects or requires it.

3. What MoniSa does

MoniSa triages, contains, investigates and documents the event; limits further access; preserves evidence; assesses risk; coordinates with clients and providers; and makes legally required notifications, including applicable CERT-In, DPDP and GDPR notifications. Notification timing depends on the governing law and facts—this page does not promise that every report is a legally reportable breach.

4. Responsible disclosure

Good-faith reports are welcome. Do not access more data than necessary to demonstrate an issue, alter records, disrupt service, use social engineering, demand payment, or disclose the issue publicly before MoniSa has had reasonable time to investigate and remediate. This is not a bug-bounty offer.