Vakt Vakt Early Adopter

Service Level Agreement

Vakt Pro · Version 2.0 · September 2026

Deutsche Fassung: sla

1. Scope

This document describes support and maintenance for Vakt Pro (annual plan EUR 2,990 net or monthly plan EUR 299 net, per single instance) running on the customer's own infrastructure (self-hosted).

The provider has no access to the customer's instance or data. All commitments cover software support and maintenance only, not the operation of the instance.

NorvikOps is a sole proprietorship. The commitments in this document are deliberately sized so that one person can reliably meet them.

2. Targets, not guarantees

All time frames in this document are targets. The provider makes reasonable efforts to meet them. Missing them does not give rise to penalties, service credits or price reductions.

There is no entitlement to a specific resolution time, to availability (uptime) or to being reachable at fixed hours.

3. Support

  • Channel: e-mail to [email protected]. No phone, chat or video support, no scheduled calls.
  • Handling: on business days (Monday to Friday, excluding public holidays at the provider's seat), without fixed hours.
  • Response target: first reply (acknowledgement, follow-up question or answer) within 3 business days.
  • Community: best effort via GitHub Issues, no commitment.

4. Security vulnerabilities

  • Reporting: to [email protected], please not as a public GitHub issue.
  • Acknowledgement: target 3 business days.
  • Remediation: confirmed vulnerabilities take priority over all other work. Target for severe vulnerabilities (CVSS ≥ 7.0): a patch within 14 calendar days of confirmation; actively exploited vulnerabilities as fast as possible.
  • Statutory reporting obligations of the provider (e.g. under the Cyber Resilience Act) remain unaffected.

5. Software updates

  • Bug fixes and security patches are released for the current version. Older versions are not patched retroactively; the customer upgrades to the current version.
  • Semantic Versioning: bug fixes → PATCH, new features → MINOR, breaking changes → MAJOR.
  • Breaking changes are announced at least 4 weeks in advance in the release notes. Every MINOR and MAJOR release comes with upgrade notes.

6. Absence

During holidays, illness or other unavailability of the provider, the targets are suspended. Absences of more than 5 business days are announced via automatic e-mail reply stating the expected return date.

7. Not included

  • Operation, monitoring, backup and restore of the customer's instance
  • Direct server access or remote maintenance on the customer's infrastructure
  • Third-party software: Trivy, Nuclei, OpenVAS, Ollama and external AI providers (e.g. OpenAI, Mistral), PostgreSQL, Redis, Docker, Caddy, Nginx, Casdoor
  • Custom modifications, modified source code and configurations outside the official documentation
  • Training, workshops and compliance or certification consulting
  • Managed hosting (separate contract)

8. Customer obligations

  • Run a current version (at most 2 minor versions behind the latest release)
  • Report issues with sufficient context (version, log excerpts, steps to reproduce)
  • Meet the system requirements from the installation documentation
  • Keep regular backups of database and uploads and test the restore
  • Review AI-generated content (e.g. policy drafts, reports) before use — it is a draft

9. Liability and precedence

Liability is governed exclusively by the Terms (AGB). This document contains no liability provisions of its own. In case of conflict, the Terms prevail.

10. Changes

The provider may change this document with 30 days' notice by e-mail. Material deteriorations entitle the customer to terminate the current subscription for cause.

11. Contact