Indusface

Service Level Agreement

1. Objective

The objective of Indusface is to provide complete protection to all the applications that have subscribed to its solution, by:

  • Finding vulnerabilities in applications through automated application scans
  • Providing Manual Pen Testing to find business logic vulnerabilities in applications
  • Providing Proof of Concepts for vulnerabilities found by scanner, on request
  • Protecting applications against Layer 7 attacks through WAF deployed in-line with the traffic
  • Protection against Layer 7 DDoS attacks
  • Monitoring and updating WAF rules to ensure deployment in log & block mode without false positives

2. Scope of Service Level Agreement

This document describes the standard level of service rendered by Indusface within the framework of Security, including performance criteria, availability of services, action to be taken in cases of a service failure, and response and repair times.

Indusface has the right to change, update, amend or modify this SLA at any time. Such changes will be intimated to the customer.

3. Additional Definitions

For the purpose of this agreement, the following additional definitions apply:

  • False positive in WAF — Blocking of a legitimate request as a malicious request.
  • POC (Proof of Concept) — Proof given to show or validate the existence of a vulnerability found by the scanner in the application.
  • Management of WAF rules — Monitoring of rules to ensure they are working and fine-tuning them to avoid false positives.
  • Layer 7 DDoS event — A surge of traffic in such a way that the host-based DDoS alert configured for the application is triggered.
  • Manual Pen Testing — Testing done by security experts using standard ethical hacking techniques to identify vulnerabilities that are difficult to find using automated scanners.
  • Response time — The first response time taken by the Indusface team to respond to an issue or query raised by the customer.
  • WAF configuration — The configuration & rules on the WAF applied by Indusface to ensure protection of the web application.
  • Virtual Patches — WAF rules written by the Indusface team to protect against application vulnerabilities.
  • NI (Network Infrastructure) — The group of Indusface controlled systems (servers, hardware, and associated software) responsible for delivering the Services.
  • Outage event — Any event resulting in complete unavailability of a web application configured for protection, due to WAF configuration applied by Indusface or unavailability of Network Infrastructure.
  • PI (Peripheral Infrastructure) — Indusface's Portal and its APIs.
  • PI Outage — A period when the Indusface PI is unavailable, outside a Scheduled Maintenance window.
  • Scheduled maintenance — Maintenance work performed by Indusface to the WAF configuration or other peripheral components. Indusface will notify the customer by email at least 48 hours before the scheduled maintenance.
  • Application availability — The amount of time, expressed as a percentage, during which the application configured for protection is available over the defined period.
  • PI availability — The amount of time, expressed as a percentage, during which the PI is available to the customer over the defined period.
  • Onboarding support — Support provided by Indusface to understand customer requirements, provide configuration suggestions, and assist with changes needed to onboard a site successfully.
  • Indusface business hours — Monday to Friday, 9am to 6pm IST.

4. Uptime Commitment

Indusface provides an application availability commitment of 100% and a PI availability commitment of 99.9% per month.

5. Service Level Commitments

  • Proof of Concept (POC) for vulnerabilities found through web application security scanning and requested from the portal, will be delivered within the following timeframes (business hours):
    • Critical Vulnerabilities — Within 24 Business Hours
    • High Vulnerabilities — Within 48 Business Hours
    • Medium Vulnerabilities — Within 72 Business hours

    POC is not available for vulnerabilities with severity level of Low and Info.

  • Virtual Patches in WAF will be created if the customer requests patching of newly discovered vulnerabilities. Estimated delivery times (business hours):
    • Critical Vulnerabilities — Within 24 Business hours
    • High Vulnerabilities — Within 48 Business hours
    • Medium Vulnerabilities — Within 72 Business hours

    Virtual Patching is not available for vulnerabilities with severity level of Low and Info.

  • WAF rules will be monitored and updated to ensure zero false positives within 14 days of onboarding completion.
  • DDoS event notification: Customers will be notified within 2 minutes of DDoS event detection by Indusface.
  • Manual Pen-Testing will be completed within 4 weeks of request raised by the customer.
    • Though not mandatory, the customer can choose to fix vulnerabilities and request validation of those fixes within 60 days from the report availability date.
  • SwyftComply — Vulnerabilities that can be patched by WAF will be patched, validated, and a clean report provided within 72 hours.

6. Support Process

Severity Levels

Indusface uses a formal severity ranking system to prioritize support cases. The severity level reflects the importance and impact of a particular case on the customer's business.

Dynamic Adjustment: During the lifecycle of an open case, the severity ranking may be adjusted to reflect the current business impact. For example, if a previously low-priority problem becomes more urgent, its severity can be increased. Conversely, if a suitable workaround is implemented, the severity may be downgraded to a lower level.

Exceptions to Severity Levels

The stated severity levels apply only to production systems. Issues affecting non-production systems (e.g., test, development, sandbox) are automatically downgraded by one severity level.

Response Times

  • Indusface will make commercially reasonable efforts to respond to cases within the target response times outlined in the tables below.
  • These Response Times are targets only, not guarantees.
  • Indusface does not commit to fixed resolution times or delivery dates.
  • Response Times may vary depending on the nature and complexity of the case.
  • Response Times don't apply when support is waiting for the customer to respond.
  • The stated Response Times apply only if the support request is raised through official Indusface Support Channels.

Infrastructure — Severity Level Commitments

Severity criteria are common across all support plans — response and status-update commitments vary by plan.

  Severity 1 — Critical Severity 2 — High Severity 3 — Medium
Criteria Severe business impact on, or downtime of, client service(s) to their end customer due to issues with Indusface services Degradation of client service(s) to their customers due to a malfunction of Indusface services Other issues that do not impact client service(s) to their customers
Standard
  Severity 1 — Critical Severity 2 — High Severity 3 — Medium
Initial Response Time 2 hrs 4 hrs 24 hrs
Status Update 2 hrs 1 business day 4 business days
Mode Email
Premium
  Severity 1 — Critical Severity 2 — High Severity 3 — Medium
Initial Response Time 30 mins 1 hr 8 hrs
Status Update 1 hr 4 hrs 1 business day
Mode Email / Chat / Telephone

Software — Severity Level Commitments

Severity criteria are common across all support plans — response and status-update commitments vary by plan.

  Severity 1 — Critical Severity 2 — High Severity 3 — Medium Severity 4 — Low
Criteria A critical technical issue resulting in a total loss of core functionality in the Software, or inoperability of the Software in production (e.g. portal not accessible), that critically affects the customer's business operations. No workaround is available. A major technical issue resulting in severe performance problems in the Software having a severe impact on the customer's business operations (for example, SIEM API not working). No workaround is available. A non-critical component is malfunctioning, causing moderate impact on the customer. A workaround forces a user and/or system administrator to use a time-consuming procedure to operate the system, or removes a non-essential feature. A minor technical issue where the customer can continue to use the service with minor inconvenience.
Standard
  Severity 1 — Critical Severity 2 — High Severity 3 — Medium Severity 4 — Low
Initial Response Time 2 hrs 4 hrs 8 hrs 1 business day
Status Update Once a day (minimum) Every other day (minimum) Once per week (minimum) As appropriate
Mode Email
Premium
  Severity 1 — Critical Severity 2 — High Severity 3 — Medium Severity 4 — Low
Initial Response Time 30 mins 1 hr 8 hrs 1 business day
Status Update Once a day (minimum) Every other day (minimum) Once per week (minimum) As appropriate
Mode Email / Chat / Telephone

7. Support Coverage

Indusface commits to the following support availability:

Channel Standard Premium
Chat 24×7×365 24×7×365
Email 24×7×365 24×7×365
Telephone - 24×7×365

Escalation Support Tel — IN: +91 265 6133083  |  US: +1 866 537 8234

Emailsupport@indusface.com

Escalation Chain

In case of unresolved concerns or technical issues, follow the escalation chain below. The initial response will arrive within one business day.

Indusface Support Manager — support-manager@indusface.com

8. Penalty Credits

Submission of Claims

To submit a claim for Credits, the customer must open a support ticket with Indusface technical support within seven (7) calendar days (168 hours) after the Outage occurred. The ticket must include detailed descriptions of the Outage, its duration, network traceroutes, the site(s) affected, and any attempts made to resolve the Outage. The ticket must mention the claim for credit.

Review of Claim

Indusface will use all information reasonably available to it to validate claims and make a good faith judgment on whether there was an Outage and if Credits apply.

Exceptions

Credit is not applicable in the case of outage:

  • Due to factors outside Indusface's reasonable control
  • That resulted from Customer's or third-party hardware or software
  • That resulted from actions or inactions of Customer or third parties
  • Caused by Customer's use of the Service after Indusface advised the Customer to modify its use, if the Customer did not modify its use as advised
  • During beta and trial Service (as determined by Indusface)
  • Attributable to the acts or omissions of Customer or Customer's employees, agents, contractors, or vendors, or anyone gaining access to Indusface's Service through Customer's Authorized Users' accounts or equipment

Credit Calculation

On review of a claim, if Indusface accepts it, the customer will receive compensation in the form of credit, calculated as follows:

  • In case of an Uptime commitment not honoured for a particular web application, Indusface commits to pay back for each day of outage 1/365th of payment collected for annual billing and 1/30th for monthly billing.
  • In case of a Service Level commitment not honoured for a particular web application, Indusface commits to pay back for each day of delay 1/365th of payment collected for annual billing and 1/30th for monthly billing.
  • In case of a Software Support commitment not honoured, Indusface commits to pay back for each day of delay 1/365th of payment collected for annual billing and 1/30th for monthly billing.
  • Cumulative penalty cannot exceed 30 days of credit at any point.