| name | breach-notification-ui |
| description | Use when designing the UI for a security breach notification (rare but high-stakes). Covers tone, what to disclose, the in-app banner + email + status page pattern, and the legal requirements that affect design.
|
Breach Notification Ui
Breach notification is the highest-stakes UI you'll ever design. Get it right by being honest, fast, and specific.
Timing
Most jurisdictions require notification within 72 hours of confirmed breach. Design assumes this clock is running.
Channels
In-app banner (sticky, dismissible after read) + email (to all affected) + status page update + dedicated incident page. Same message across all.
What to disclose
What happened. When it happened. What data was affected. What you've done. What customer should do. Contact for questions. Acknowledged without legal hedging.
Tone
Direct, accountable, specific. NEVER 'we take security seriously' boilerplate. NEVER passive voice ('mistakes were made').
Follow-up
Post-mortem published within 30 days. Action items. Public.atus updates as situation evolves.
Common mistakes
Hiding the notice. Legal-edited into uselessness. Passive voice ('an unauthorized party gained access'). No specific affected-data description. 'We take this seriously' platitudes. No acknowledgment of trust damaged.
Where this fits in X3 Compass
Applied in the X3 Compass build via the relevant pages and components.