---
title: Incident & Breach
description: Incident response and breach notification at Langfuse.
---

# Incident & Breach

## Incident Response

We follow a standard incident identification and response process. We post status updates on our [status page](https://status.langfuse.com).

## Notification

We will notify customers of any breach without delay. At most within 72 hours.

## Incident Response Plan

Our Incident Response Plan provides a structured framework to ensure we detect and react to security incidents swiftly, requiring all personnel to report any suspected event within 24 hours. Once an incident is reported, it is investigated and assigned a severity level within 48 hours, which dictates the priority and timeline for the response. A dedicated team then works to contain, resolve, and recover from the incident, preserving forensic evidence and meticulously documenting all actions taken. Following resolution, we conduct a post-mortem analysis to identify the root cause, and in the event of a data breach involving sensitive information, we are committed to notifying all affected parties and relevant authorities.

<!-- agent-instructions -->

---

## Agent Instructions

This page is part of the [Langfuse](https://langfuse.com) documentation, published as plain Markdown for AI agents. Every page is available as Markdown by appending `.md` to its URL, or by sending an `Accept: text/markdown` header. This page: `https://langfuse.com/security/incident-and-breach.md`.

### Querying these docs

If the answer is not on this page, query the documentation instead of guessing:

- **Semantic search** across all Langfuse docs, returning an answer with the relevant pages and excerpts. Ask a specific, self-contained question:

  ```bash
  curl -sG "https://langfuse.com/api/search-docs" --data-urlencode "query=How do I trace a LangGraph agent?"
  ```

- **Index of every page**: <https://langfuse.com/llms.txt>, with per-section indexes [llms-docs.txt](https://langfuse.com/llms-docs.txt), [llms-integrations.txt](https://langfuse.com/llms-integrations.txt), and [llms-self-hosting.txt](https://langfuse.com/llms-self-hosting.txt).

### Before writing Langfuse code

- **Install the [Langfuse Agent Skill](https://langfuse.com/docs/api-and-data-platform/features/agent-skill).** It encodes Langfuse's own best practices for instrumentation, prompt management, and evaluation, and materially improves results.
- **Read [What does a good trace look like?](https://langfuse.com/docs/observability/best-practices.md)** before instrumenting an application.
- **Verify endpoints, parameters, and response fields** against the [API reference](https://api.reference.langfuse.com) instead of inferring them from code examples.
- **Use the [Langfuse CLI](https://langfuse.com/docs/api-and-data-platform/features/cli)** (`npx langfuse-cli api <resource> <action>`) to read or write traces, prompts, datasets, and scores from the terminal.

Found an error in these docs? Please open an issue at <https://github.com/langfuse/langfuse-docs/issues>.
