Evidence before assertion.
Response under authority.

SwarmWard ASDR continuously observes outside-in signals that may indicate profiling, exposure, compromise, or coordinated swarm targeting. This standard describes how we validate a finding, protect sensitive evidence, notify an authorized recipient, and begin managed response with the MSP.

Our operating covenantSecure disclosure before detailed evidence. Clear confidence and limitations. Managed response coordinated through the MSP and its authorized security team.
01

What this standard covers

It applies when SwarmWard identifies externally observable activity associated with a potentially exposed MSP or managed client. A finding may include reconnaissance, leaked access, exposed services, impersonation, attacker infrastructure, or patterns consistent with coordinated agentic targeting.

An initial alert is an analytic signal. SwarmWard validates and investigates within the agreed service scope; a formal breach determination, legal notification, or regulatory conclusion remains the responsibility of the customer and its counsel.

02

Evidence gate

  1. Confirm that the observed asset is attributable to the MSP or managed client.
  2. Confirm lawful source provenance and preserve timestamps, indicators, limitations, and plausible alternatives.
  3. Assign a confidence level and require second-person review for high-severity disclosures.
  4. Describe what the evidence supports without overstating an unconfirmed breach.
03

How we contact you

We first use a published vulnerability-disclosure policy, security.txt record, monitored security mailbox, or known executive security contact. The initial notice contains only enough information to authenticate the matter; sensitive evidence is not attached to ordinary email.

MINIMAL NOTIFICATIONConfidential security finding requiring an authorized recipient

We identified externally observable activity associated with assets attributed to your organization that may indicate an active security exposure. We have not concluded that a reportable incident occurred. We would like to share the evidence through your authorized, encrypted disclosure channel.

04

Secure evidence handling

  • Verify the recipient through an independent channel.
  • Use least-privilege access, MFA, expiration, and a case identifier that does not expose the recipient.
  • Share only necessary evidence; avoid unnecessary personal data, credentials, or secrets.
  • Record access and acknowledgment, then apply the configured retention and deletion schedule.
05

Managed response

Once an authorized MSP recipient accepts the finding, SwarmWard can move from disclosure into the contracted response process: validate exposure or compromise, prioritize affected clients, investigate swarm activity, recommend containment, and coordinate approved action through the MSP's identity, endpoint, email, firewall, backup, RMM, and incident-response capabilities.

The MSP retains customer authority and owns remediation execution unless a separate agreement assigns a specific action to SwarmWard or another response provider.

06

What recipients receive

  • Case identifier, executive summary, and affected authorized asset
  • Observation timeline, source provenance, indicators, severity, and confidence
  • Known limitations and reasonable alternative explanations
  • Recommended validation, containment, escalation, and pre-attack remediation steps
  • Clear response ownership, next update, and evidence-retention expectations

Need to receive or validate a finding?

Contact SwarmWard โ†—