Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Data breach assessment

Was data exfiltrated during your WordPress hack?

We review available files, database, user changes, access and server logs, outbound connections, and other traces for credible indicators of possible data exfiltration. You receive a documented assessment that includes the limits of the available evidence — not a blanket all-clear, and not a claim that goes beyond what the data actually shows.

After a WordPress hack, it is important to establish whether customer or user data may have been affected. We review the available technical traces and document what conclusions they support and where evidence is missing.

What we check

Depending on the logs and system access available, we review indicators including:

Limits of what we can state — what a result means and what it doesn't

We distinguish between a finding (a clearly established fact), anindicator (a signal that supports a possibility without proving it), and alimit (what the available data cannot show). We apply this classification to every relevant trace in the final report.

Befund / Finding
A negative result means: "No credible indicators were found in the available data."
Grenze / Limit
It does not mean: "It is technically ruled out that data was exfiltrated."
Indiz / Indicator
If logs are missing, incomplete, or were tampered with by the attacker, the strength of any assessment drops accordingly. We state these gaps explicitly instead of glossing over them.

Notification duties for personal data

A notification to the supervisory authority may be required under GDPR Article 33 and must then be made without undue delay, where feasible within 72 hours of becoming aware. Article 34 concerns informing affected individuals where the breach is likely to result in a high risk.

We do not make that legal determination for you and cannot make it conclusively. It remains with you as the data controller and your data protection officer or legal counsel. We document the available technical findings and evidence gaps as a basis for that decision.

Suspect a data breach? We review the available traces.

Frequently asked questions about data breaches and GDPR

Can you prove that no data was exfiltrated?

No, and no credible provider promises that. We review the available evidence for credible indicators. A negative result means that no credible indicators of exfiltration were found in the available data — not that exfiltration is technically ruled out.

Do I have to report a data breach to a supervisory authority?

A notification to the supervisory authority may be required under GDPR Article 33 and must then be made without undue delay, where feasible within 72 hours of becoming aware. Article 34 concerns informing affected individuals where the breach is likely to result in a high risk. As the controller, you should assess whether these conditions apply, with data protection or legal advice where appropriate.

What if your review finds no indicators, but I'm still not sure?

That is understandable. Our report states exactly which logs and data sources were available and where the gaps are. Based on that, you and your data protection officer or legal counsel can decide together whether further steps make sense.

Do you provide court-admissible digital forensics?

No. Our data-breach assessment is an indicator-based technical review, not a court-admissible forensic investigation. If your case requires that, we tell you so and state the limits of our scope clearly in the report.