← Incident logEditorial standard
Severity criteria
Every incident's level (Critical, Major, Minor) and its 1–10 score follow these criteria. If you send us an incident, covering the three factors below helps us rate it accurately.
Three factors
- ReachDid it stay with the operator, or reach users, customers or third parties?
- ReversibilityCould what was lost, leaked or spent be recovered?
- Time to detectHow long did it go unnoticed?
Three levels
Irreversible, or left open to abuse by a third party
Any of these
- Real users or customers suffered actual harm to their money, personal data or data
- Lost data or information that was sent out cannot be recovered
- Secrets or systems were open to abuse by a third party until someone noticed (counts even when no abuse was confirmed)
Examples on this site
- Mass theft of card data
- An API key left in plain text in Git history
- Live sites still loading scripts from a lapsed domain
Real damage, but contained and recovered with effort
Any of these
- The damage stayed within the operator’s own systems and was recovered
- But recovery took real time or money, detection took days, or a safety control failed silently
- It affected someone else’s decision or process, and was corrected
Examples on this site
- A scheduled job silently stopped for five days
- An API key printed to a log and rotated right away
- A read-deny rule silently stopped working
Small impact, noticed quickly and undone easily
Any of these
- Cost an interrupted task, a redo, or burned usage limits
- Noticed quickly and easy to undo
- Caught before any harm (a near miss)
Examples on this site
- Parallel review agents burned a usage limit in minutes
- Browser page translation broke a web app
Within a level, the score moves toward the top of its band the more of the three factors apply and the wider and longer the impact.
Notes
- Behavior seen in an evaluation or a researcher’s proof of concept, with no real users harmed, is rated on the harm it could have caused and may sit one level below a production incident.
- Incidents known only from reporting (unverified) are rated on what was reported, and the entry says it is unverified.
- The more concretely the cause and fix are described, the more accurate the rating. Submissions that cover the three factors help a lot.