Skip to content

incident.io data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On incident.io, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.

Checks (3)

severity: high Workflow Accesses Private Data fix difficulty: medium #

Disable private incident and escalation access in Incident.io workflow settings unless strictly required

  1. Sign in to Incident.io and navigate to Workflows
  2. Open the workflow flagged by this policy
  3. Click "Edit" on the workflow configuration
  4. Locate the privacy settings and uncheck options for private incident or escalation access
  5. Save the workflow and confirm it no longer references private data unless justified

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: low Public Status Page fix difficulty: easy #

Review whether public status page exposure is intended and restrict access if not required

  1. Sign in to Incident.io and navigate to Status pages
  2. Open the status page flagged by this policy
  3. Click "Settings" or "Edit" on the status page
  4. If public exposure is not required, change the visibility to private or internal
  5. Save the change and verify the status page is no longer publicly accessible

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Workflow Unconstrained on All Incidents fix difficulty: medium #

Add conditions to workflows that run on all incidents without filters to limit unintended data exposure

  1. Sign in to Incident.io and navigate to Workflows
  2. Open the workflow flagged by this policy
  3. Click "Edit" and navigate to the conditions section
  4. Add at least one condition group to restrict which incidents trigger this workflow
  5. Consider filtering by severity, type, or team to limit scope
  6. Save the workflow and test with a sample incident to confirm conditions apply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More incident.io checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial