Dashboard|

Security Incidents

Understand, monitor, and respond to security incidents detected by Holeacquisition LLC.

What are Security Incidents?

A security incident is any event where an enabled guard blocks or flags policy-violating activity in an AI request or response. Scanning is off by default, so projects with no active guard log no incidents. All fired incidents are logged for review and compliance.

Incident Types

TypeDescriptionAction when guard is enabled
PII DetectionPersonal data found in promptBlock (input)
Prompt InjectionAttempt to manipulate AI behaviorBlock (input)
Content FilterHarmful content matched by policyBlock (only via governance / custom rule for output)
Rate LimitUsage quota exceededBlock
Suspicious PatternUnusual usage detectedLog

With the master switch off and no custom rule or governance policy, PII / injection / content rows do not fire — requests return 200 OK and no incident is written.

Severity Levels

Low

Minor policy violations or potential false positives. Review periodically.

Medium

Clear policy violations but not urgent. Review weekly.

High

Serious violations like prompt injection attempts. Review immediately.

Critical

Potential security breaches or coordinated attacks. Investigate urgently.

Viewing Incidents in Dashboard

  1. Navigate to your project dashboard
  2. Click "Security" in the sidebar
  3. View the incidents list with:
    • Incident ID
    • Type and severity
    • Timestamp
    • User/API key info
  4. Click any incident to view full details

Incident Details

Each incident record contains:

  • Incident ID: Unique identifier for tracking
  • Timestamp: Exact time of detection
  • Type: PII, prompt injection, etc.
  • Severity: Low, medium, high, critical
  • Request Context: Model, user ID, project
  • Detection Details: What triggered the incident
  • Action Taken: Blocked, logged, or allowed
  • Redacted Prompt: The input (with PII removed)

For Low Severity:

  • Review monthly
  • Look for patterns
  • Adjust filter sensitivity if needed

For Medium Severity:

  • Review weekly
  • Educate users if accidental
  • Consider user warnings

For High/Critical Severity:

  • Investigate immediately
  • Identify the user/source
  • Consider account suspension
  • Review security policies

The Security dashboard shows trends over time:

  • Incidents per day/week/month
  • Breakdown by type
  • Severity distribution
  • Top users/API keys flagged
  • Geographic distribution (if available)

Accessing Incidents via API

Fetch incidents programmatically for custom alerting. The dashboard uses a project-scoped endpoint:

// GET /api/projects/{projectId}/security/incidents
const response = await fetch(
  'https://cencori.com/api/projects/proj_123/security/incidents?severity=high',
  {
    headers: {
      // Uses your authenticated dashboard session
      // (this endpoint is not part of the public API)
    }
  }
);
 
const { incidents } = await response.json();
 
incidents.forEach(incident => {
  console.log(`[${incident.severity}] ${incident.type} at ${incident.timestamp}`);
  
  if (incident.severity === 'critical') {
    // Send alert to Slack, PagerDuty, etc.
    sendAlert(incident);
  }
});

Compliance and Audit Trails

Security incidents provide audit trails for compliance:

  • SOC 2: Demonstrate security monitoring and incident response
  • GDPR: Proof of data protection measures
  • HIPAA: PHI access logging
  • ISO 27001: Information security management

Export incident logs for auditor review in CSV or JSON format.

Best Practices

  • Review high/critical incidents within 24 hours.
  • Set up email/Slack alerts for critical incidents.
  • Document your incident response process.
  • Train team members on recognizing attack patterns.
  • Export logs monthly for compliance records.
  • Use incident trends to improve security policies.