Service Level Agreement
Neo's availability guarantee, incident severity classifications, and response and remediation commitments.
This Service Level Agreement (“SLA”) sets forth the service level commitments provided by Neo Security, Inc. regarding the availability and support of the Service.
Service Availability Commitment
Neo Security, Inc. is committed to providing a high-quality, reliable environment for enterprise cybersecurity defense. We guarantee that the Service will be available and operational with an Uptime of 99.9% during any calendar month.
Incident Severity and Escalation
Incidents are classified based on their impact on the production environment and the sensitivity of the data involved. The following definitions and escalation paths apply:
- P0 (Critical): Evidence of active exploitation. This includes, but is not limited to, unauthorized access to production AWS, RDS, or telemetry S3; compromise of customer telemetry data; active credential compromise; or unauthorized data exposure via the dashboard.
- Escalation: Immediate notification to senior management.
- P1 (High): Suspected unauthorized access. Examples include anomalous CloudTrail activity, critical production CVEs, or the loss of an unencrypted device with production access.
- Escalation: Document the incident and notify the appropriate manager via Slack.
- P2/P3 (Medium/Low): Suspicious or odd behaviors. This includes phishing attempts, failed authentication logs, or the loss of an encrypted device.
- Escalation: Track and assign the incident to the appropriate department for review and resolution.
Remediation SLAs
Neo Security, Inc. adheres to the following response and remediation timelines based on incident severity:
| Severity | Response Time | Remediation Time |
|---|---|---|
| P0 — Critical | 1 hour | 10 Days |
| P1 — High | 3 hours | 30 Days |
| P2 — Medium | 6 hours | 45 Days |
Questions about this document? Contact legal@neo.ai.