Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
A small company can make a small number of promises and keep them. This page is the set we are willing to be held to — how to reach us, what we do first, and when you hear from us.
Last reviewed August 22, 2026
You do not need to be certain, and you will not be charged for a false alarm. A suspicion reported in ten minutes is worth more than a confirmed finding reported next week. Use either channel — both reach the same people.
Fastest during Monday–Friday, 9:00 AM – 6:00 PM Central. Outside those hours, leave a message and send the email as well.
Put “security” in the subject line. Monitored outside business hours, though a reply may wait until the next business morning.
Helpful in a first report: what you saw, when you saw it, the account or tenant involved, and anything you have already changed. Please do not include passwords or secrets in the message — if a credential is exposed, rotate it and tell us that you have.
The same order every time, so that under pressure nobody has to invent a process.
A person replies to say we have it and who is handling it. Within business hours that is usually quick; the commitment we will hold ourselves to is your plan's support response time, below.
If something is actively exposed, the first action is to stop it — revoke a credential, disable an automation, take an endpoint out of service. Understanding exactly how it happened comes second.
Logs and configuration state are captured before anything is cleaned up, so the timeline can be reconstructed later rather than guessed at.
Which customers, which data categories, and over what period. This is the step that decides who we notify and what we can honestly tell them.
The permanent fix, and a plain-language account of what happened for the customers involved. If the cause was a decision of ours, the write-up says so.
We will notify affected customers of a confirmed security incident involving their data without undue delay.
That sentence is the whole commitment, and we have kept it short on purpose. We are not going to quote a number of hours we cannot currently prove we would meet: we do not yet run the round-the-clock monitoring that a specific breach-notification clock requires, and promising one would be a promise made on the marketing page rather than in the operations.
What a notification will contain: what happened, what data of yours was involved as far as we know at the time, what we have done, what we are still doing, and what — if anything — we need you to do. If the picture is still incomplete we will say that rather than wait for a tidy story, and we will follow up as it changes.
Where an incident involves your Microsoft 365 tenant, remember that you hold the controls too: you can revoke the application consent yourself, at any time, from your own admin center without waiting for us. The steps are on the Microsoft security page.
These are the support response commitments already in your plan. They are the only hour-based numbers on this page, and they are measured in business hours during Monday–Friday, 9:00 AM – 6:00 PM Central.
| Plan | First response |
|---|---|
| Launch | Within 8 business hours |
| Growth | Within 4 business hours |
| Scale | Within 2 business hours |
A credible security report jumps the queue regardless of plan, and free ID360 Studio accounts can report one on the same channels without a plan at all.
Reports are welcome at support@impressionsdirect360.com. We do not run a paid bug-bounty programme and will not pretend otherwise — what we offer is a prompt human reply, credit in the fix note if you want it, and no legal action against good-faith testing that avoids other customers' data, avoids degrading the service, and stops at the point a vulnerability is demonstrated.
Please test only against your own account or tenant. Reports about our vendors' own products — Microsoft, Google Cloud, Vercel, Stripe, Resend — should go to them directly; they are listed on our subprocessors page.
Contractual or legal correspondence about an incident goes to legal@impressionsdirect360.com. IMPRESSIONSDIRECT360 LLC is a Missouri limited liability company; nothing on this page varies the terms of service.