Skip to content
xenXDRby FluenceSecurity
PricingDocs
EN·PL
Sign inBook a demo
  1. XenXDR
  2. Legal
  3. Service level summary

Service level summary

How service levels for hosted tenants and the managed SOC are defined and measured. The numbers live in your contract; the definitions live here.

Version 1.0Last updated 2026-09-15Effective from 2026-09-15

On this page

  1. 1What this document is
  2. 2Scope
  3. 3Severity definitions
  4. 4Acknowledge and resolve
  5. 5Coverage window
  6. 6Measurement and reporting
  7. 7Exclusions
  8. 8Availability of hosted tenants
  9. 9Service credits
  10. 10Changes

What this document is

Service levels for the managed SOC service and for hosted tenants are agreed in the order form. This page explains the definitions and the measurement method so that the numbers in a contract mean the same thing to everyone. Where a contract states a value, it prevails.

Scope

Service levels apply to:

  • Hosted tenants: availability of the console, ingest endpoints and customer portal operated by FluenceSecurity.
  • Managed SOC: the time within which FluenceSecurity's analysts acknowledge and resolve alerts raised in the Customer's tenant, and the reports delivered.

Self-hosted deployments are operated by the Customer and have no availability service level from FluenceSecurity; support response times apply instead.

Severity definitions

Alert severity is set by the detection that raised the alert and may be adjusted by an analyst during triage. The levels used across the Platform are:

SeverityMeaning
CriticalStrong indication of active compromise or imminent damage, such as credential dumping, ransomware activity or confirmed lateral movement.
HighLikely malicious activity requiring prompt investigation.
MediumSuspicious activity that needs a look during the shift.
LowInformational or policy signals with no immediate risk.

Acknowledge and resolve

  • Time to acknowledge is measured from the moment an alert is written to the queue to the moment an analyst takes ownership of it in the Platform.
  • Time to resolve is measured from the same start to the moment the alert is closed with a disposition or escalated into a case, whichever comes first. Cases have their own handling times, agreed in the contract.

Targets are set per severity in the order form. Typical targets for a 24x7 contract are: acknowledge within 30 minutes for critical and 1 hour for high alerts; resolve or escalate within 1 hour and 2 hours respectively.

Coverage window

Each organisation has a coverage window: either 24x7 or business hours in the Customer's time zone, as agreed. Outside a business-hours window the clock does not run, and alerts raised outside the window are measured from the start of the next window. The Platform records the window and applies it automatically to every measurement.

Measurement and reporting

Measurements are taken by the Platform, not by hand. Timestamps for queue entry, acknowledgement and closure are write-once, and the monthly SLA report in the customer portal shows, per severity, the number of alerts, the share met, breached and pending, and the median times. The same figures are visible to the Customer at any time.

Exclusions

The following are excluded from service level measurement:

  • alerts on telemetry the Customer's own infrastructure delayed by more than one hour;
  • periods during which the Customer's tenant was unavailable because of the Customer's actions, including revoked credentials or disabled integrations;
  • scheduled maintenance announced at least 48 hours in advance, limited to 440 minutes per month;
  • events of force majeure.

Availability of hosted tenants

Availability is measured monthly as the share of minutes in which the console and ingest endpoints answer health checks, excluding scheduled maintenance. The target is stated in the order form; FluenceSecurity does not publish a general uptime guarantee at this stage.

Service credits

Where the order form provides service credits, a breach of a target in a month entitles the Customer to the credit stated there, applied to the next invoice. Credits are the sole remedy for a breach of service levels unless the breach results from gross negligence.

Changes

Definitions in this document may be refined as the Platform's reporting evolves. Changes do not reduce a target agreed in an existing contract.

Questions about this document?

Write to legal@fluencesecurity.com or privacy@fluencesecurity.com for privacy matters.

xenXDRby FluenceSecurity

A FluenceSecurity product
Made in Gdańsk, Poland

  • GitHub
  • LinkedIn
  • X

Platform

  • Platform overview
  • SIEM and search
  • Endpoint agent
  • Detections
  • AI triage
  • Playbooks and response
  • Alerts, cases and reports
  • Multi-tenancy and access
  • Customer portal
  • Integrations

Solutions

  • For security teams
  • For MSSPs
  • Managed SOC by FluenceSecurity

Resources

  • Documentation
  • Why XenXDR
  • Security and trust
  • Changelog
  • Pricing

Company

  • fluencesecurity.com
  • About FluenceSecurity
  • MDR service
  • Blog
  • Contact

Legal

  • Privacy policy
  • Cookie policy
  • Website terms
  • Software licence terms
  • Data processing
  • Service levels
  • Company details
  • Accessibility
  • Vulnerability disclosure
  • Subprocessors
© 2026 FluenceSecurity. All rights reserved.Sigma, Splunk, Okta, Microsoft, Fortinet and other marks belong to their respective owners.
EN·PL