What this document is
Service levels for the managed SOC service and for hosted tenants are agreed in the order form. This page explains the definitions and the measurement method so that the numbers in a contract mean the same thing to everyone. Where a contract states a value, it prevails.
Scope
Service levels apply to:
- Hosted tenants: availability of the console, ingest endpoints and customer portal operated by FluenceSecurity.
- Managed SOC: the time within which FluenceSecurity's analysts acknowledge and resolve alerts raised in the Customer's tenant, and the reports delivered.
Self-hosted deployments are operated by the Customer and have no availability service level from FluenceSecurity; support response times apply instead.
Severity definitions
Alert severity is set by the detection that raised the alert and may be adjusted by an analyst during triage. The levels used across the Platform are:
| Severity | Meaning |
|---|---|
| Critical | Strong indication of active compromise or imminent damage, such as credential dumping, ransomware activity or confirmed lateral movement. |
| High | Likely malicious activity requiring prompt investigation. |
| Medium | Suspicious activity that needs a look during the shift. |
| Low | Informational or policy signals with no immediate risk. |
Acknowledge and resolve
- Time to acknowledge is measured from the moment an alert is written to the queue to the moment an analyst takes ownership of it in the Platform.
- Time to resolve is measured from the same start to the moment the alert is closed with a disposition or escalated into a case, whichever comes first. Cases have their own handling times, agreed in the contract.
Targets are set per severity in the order form. Typical targets for a 24x7 contract are: acknowledge within 30 minutes for critical and 1 hour for high alerts; resolve or escalate within 1 hour and 2 hours respectively.
Coverage window
Each organisation has a coverage window: either 24x7 or business hours in the Customer's time zone, as agreed. Outside a business-hours window the clock does not run, and alerts raised outside the window are measured from the start of the next window. The Platform records the window and applies it automatically to every measurement.
Measurement and reporting
Measurements are taken by the Platform, not by hand. Timestamps for queue entry, acknowledgement and closure are write-once, and the monthly SLA report in the customer portal shows, per severity, the number of alerts, the share met, breached and pending, and the median times. The same figures are visible to the Customer at any time.
Exclusions
The following are excluded from service level measurement:
- alerts on telemetry the Customer's own infrastructure delayed by more than one hour;
- periods during which the Customer's tenant was unavailable because of the Customer's actions, including revoked credentials or disabled integrations;
- scheduled maintenance announced at least 48 hours in advance, limited to 440 minutes per month;
- events of force majeure.
Availability of hosted tenants
Availability is measured monthly as the share of minutes in which the console and ingest endpoints answer health checks, excluding scheduled maintenance. The target is stated in the order form; FluenceSecurity does not publish a general uptime guarantee at this stage.
Service credits
Where the order form provides service credits, a breach of a target in a month entitles the Customer to the credit stated there, applied to the next invoice. Credits are the sole remedy for a breach of service levels unless the breach results from gross negligence.
Changes
Definitions in this document may be refined as the Platform's reporting evolves. Changes do not reduce a target agreed in an existing contract.