# LeadPilot — Security Incident Response Protocol

**Document Version:** 1.0.0 (Phase 23)

---

## 1. Vulnerability Disclosure & Escalation

- **Security Contact:** `security@leadpilot.io` (or customer-configured administrator contact).
- **Triage Priority:** P0 (Tenant leak, Auth bypass) addressed within 24 hours; P1 (Privilege issue) within 48 hours.

---

## 2. API Key & Credential Revocation

In the event of an API token compromise:
1. Navigate to **Workspace Settings > API Keys** (`/settings/api-keys`).
2. Click **Revoke** on the compromised key. Revocation is instantaneous across all API gateways.
3. Generate a replacement key and update connected integrations.
