Security Service-Level Objectives
Not every vulnerability carries the same risk. We use severity-based service-level objectives to ensure the highest-risk issues receive the fastest attention.
| Severity | Initial response target | Remediation target | Typical examples |
|---|---|---|---|
| Critical | Within 24 hours | Within 5 business days | Confirmed data exposure, remote code execution, authentication bypass |
| High | Within 72 hours | Within 10 business days | Significant privilege escalation or exploitable service weakness |
| Medium | Within 1 week | Within 30 business days | Limited-impact configuration or application weakness |
| Low | Within 2 weeks | Within 60 business days | Hardening opportunities with low exploitability or impact |
💡
These targets guide prioritization, but active exploitation, customer impact, and business context can always accelerate response.