DocsSecurity & ComplianceSecurity SLA

Security Service-Level Objectives

Not every vulnerability carries the same risk. We use severity-based service-level objectives to ensure the highest-risk issues receive the fastest attention.

SeverityInitial response targetRemediation targetTypical examples
CriticalWithin 24 hoursWithin 5 business daysConfirmed data exposure, remote code execution, authentication bypass
HighWithin 72 hoursWithin 10 business daysSignificant privilege escalation or exploitable service weakness
MediumWithin 1 weekWithin 30 business daysLimited-impact configuration or application weakness
LowWithin 2 weeksWithin 60 business daysHardening opportunities with low exploitability or impact
💡

These targets guide prioritization, but active exploitation, customer impact, and business context can always accelerate response.

Was this page useful?

Subscribe to updates