← Legal Center

Support Program Policy

Outlines our operational technical support program, helpdesk SLA response times, support tiers, and troubleshooting escalation procedures for customers and channel partners.

Which support tier applies to you?

Select Standard for the default support tier included with most subscriptions. Select Enterprise if your Order Form specifies Enterprise-level support and SLAs.

Standard Last updated: July 2026

Last Updated: July 2026

This Standard Support and Service Level Policy (“Policy”) describes the standard support and maintenance services (“Support Services”) provided by ThreatModeler for its subscribed products (“Product”). This Policy is incorporated by reference into the main agreement governing your use of the Product (“Agreement”). Capitalized terms not defined herein shall have the meaning set forth in the Agreement.

1. Definitions

  • "Authorized Contact" means a named individual designated by Customer in writing who is authorized to submit support tickets and communicate with ThreatModeler's support team.
  • "Business Day" means Monday through Friday, excluding public holidays in the primary support region.
  • "Business Hours" means 09:00 to 17:00 on Business Days in the single timezone designated in the applicable Order Form (the "Designated Timezone").
  • "Designated Timezone" means the specific timezone designated in the applicable Order Form. If no timezone is specified in the Order Form, the Designated Timezone shall default to Eastern Standard Time (EST) for North American agreements, or Central European Time (CET) for international agreements.
  • "Incident" means a failure of the Product to perform materially in accordance with its official Documentation.
  • "First Response Time" means the time elapsed from when Customer properly submits a support ticket to when a qualified ThreatModeler support engineer provides an initial diagnosis and confirms they have begun active investigation.
  • "Mitigation" means an action or workaround that reduces the business impact of an Incident.
  • "Resolution" means a permanent fix that resolves the root cause of an Incident.
  • "Service Level Objective (SLO)" means a non-binding target for service performance. ThreatModeler will use commercially reasonable efforts to meet SLOs, but they are not firm commitments subject to service credits.
  • "Support Portal" means ThreatModeler's primary support platform, currently located at https://support.threatmodeler.com.

2. Support Tiers, Channels, and Personnel

2.1. Support Tiers. Customer will receive Standard Support Services as specified in the applicable Order Form. ThreatModeler will provide Support Services strictly during local Business Hours in the Designated Timezone, Monday through Friday. No support services, human or automated, are provided outside of Business Hours or during weekends under this Support tier.

2.2. Support Channels. All support requests must be initiated via:
(a) The Support Portal (recommended); or
(b) Email to support@threatmodeler.com.

2.3. Authorized Contacts. Customer may designate up to four (4) Authorized Contacts to interact with the support team.

2.4. Support Language. All Support Services, ticketing communications, documentation, and live interactions under this Policy are provided strictly and exclusively in the English language.

3. Incident Management & Service Levels

3.1. Incident Submission. To receive Support Services, an Authorized Contact must submit a support ticket through a designated Support Channel. The submission must include a suggested Severity Level and all information reasonably necessary for ThreatModeler to diagnose the Incident.

3.2. Severity Levels. ThreatModeler will categorize Incidents according to the definitions below. ThreatModeler reserves the right, acting reasonably and in consultation with Customer, to reclassify the severity level based on the demonstrable business impact.

SeverityDescription of Business Impact
UrgentThe production instance of the Product is completely unavailable, or a critical core functionality is unusable for all users, with no workaround available.
HighA critical Product functionality is unavailable or significantly degraded, severely impacting a majority of users or key business services, with no reasonable workaround available.
NormalOne or more non-critical features are not functioning correctly, or a major issue exists for which a reasonable workaround is available.
LowGeneral "how-to" questions, requests for information, configuration assistance, or non-critical issues with a minor impact on business operations.

3.3. Service Level Commitments and Objectives. ThreatModeler will use commercially reasonable efforts to meet the targets outlined below. First Response Time is a firm Service Level Agreement (SLA), while Mitigation and Resolution targets are Service Level Objectives (SLOs).

SeverityFirst Response Time (SLA)Next Response Target (SLO)Mitigation Target (SLO)Resolution Target (SLO)
Urgent4 Business Hours4 Business Hours1 Business Day2 Business Days
High6 Business Hours12 Business Hours72 Business Hours7 Days
Normal8 Business Hours8 Business HoursN/AN/A
Low12Business Hours12 Business HoursN/AN/A

3.4. Post-Mitigation Commitment. Upon providing a Mitigation for an Urgent or High severity Incident, ThreatModeler commits to using commercially reasonable efforts to develop a permanent Resolution and will provide Customer with a plan for such Resolution upon request.

3.5. Pausing of Service Level Clock.

(a) ThreatModeler's time-based obligations under this Policy will be paused if ThreatModeler is awaiting a response or required information from Customer. The clock will resume once the dependency is resolved.

(b) If Customer fails to respond to a Support request or inquiry from ThreatModeler within five (5) consecutive Business Days, ThreatModeler reserves the right to close the support ticket automatically due to inactivity.

4. Uptime Commitment (Applicable to Cloud Deployments Only - Standard Tier)

4.1. Uptime SLA. ThreatModeler will use commercially reasonable efforts to make the Product available with a monthly Uptime Percentage of at least 99.5% (the "Uptime Commitment"). Uptime and availability shall be measured solely and exclusively using ThreatModeler's internal system logs and monitoring tools, which shall serve as the sole and final source of truth for any availability claims.

4.2. Definitions for Uptime.
"Downtime" means the total number of minutes during which the production instance of the Product's core login and modeling functionalities are completely unavailable to Customer. Downtime does not include partial degradations or any unavailability arising from Scheduled Maintenance or Excusable Downtime.
"Monthly Subscription Fee" means one-twelfth (1/12th) of the total annual subscription fees paid for the specific, affected Product, excluding any professional services, training, or taxes.
"Scheduled Maintenance" means planned maintenance announced at least 48 hours in advance. ThreatModeler will use commercially reasonable efforts to schedule such maintenance during non-peak hours (typically, weekend windows).
"Excusable Downtime" includes any unavailability resulting from: (a) a Force Majeure Event; (b) Customer's or its users' breach of the Agreement; (c) Customer's, its users', or local internet service providers' equipment, software, or network failures; (d) any performance degradation, congestion, or outage of the underlying third-party cloud infrastructure providers (including but not limited to AWS, Microsoft Azure, or Google Cloud) or global internet backbone carriers; or (e) malicious third-party acts, including DDoS attacks, not under ThreatModeler's direct control.

4.3. Service Credits and Uptime Thresholds. If the monthly Uptime Percentage falls below the Uptime Commitment, Customer may request a service credit ("Service Credit") calculated strictly as a percentage of the Monthly Subscription Fee as set forth below:

Monthly Uptime PercentageService Credit (% of Monthly Subscription Fee)
98.5% to 99.49% 5%
Below 98.5% 10%

4.4. Service Credit Procedures and Limitations.

(a) Sole and Exclusive Remedy. The Service Credits set forth in this Section 4 constitute Customer's sole and exclusive remedy, and ThreatModeler's sole liability, for any downtime, outages, service interruptions, or unavailability of the Product. Customer expressly waives any right to claim direct, indirect, consequential, or incidental damages for service unavailability.

(b) Claim Deadline. To receive a Service Credit, Customer must submit a written request via the Support Portal within fifteen (15) calendar days of the end of the calendar month in which the downtime occurred. Failure to submit the request within this timeframe shall constitute an irrevocable waiver of the right to receive such Service Credit.

(c) Cap and Exclusions. The total aggregate Service Credits issued under this Policy for any single calendar month shall be capped at thirty percent (30%) of the Monthly Subscription Fee. Service Credits have no cash value, are non-refundable, and can only be applied to future invoices. No Service Credits will be issued if Customer is past due on any payments or otherwise in breach of the Agreement.

5. Exclusions & Limitations

5.1. General Exclusions. Support Services do not cover problems arising from: (i) Customer's negligence or misuse of the Product; (ii) any third-party products not provided by ThreatModeler; (iii) use of the Product not in accordance with the Documentation; or (iv) any modification by anyone other than ThreatModeler.

5.2. Unsupported Versions. Support Services apply only to the current major version of the Product and the immediately preceding major version. ThreatModeler has no obligation to provide Support Services for older versions.

5.3. On-Premises and Non-Production Environments .

(a) For any Product deployed on-premise, the Mitigation Targets, Resolution Targets, and all Service Credits or Uptime Commitments under Section 4 of this Policy shall not apply.

(b) For the avoidance of doubt, the SLAs and SLOs specified in Section 3 of this Policy apply strictly to Customer's active production environments of the Product. ThreatModeler is not bound by any SLAs or SLOs for non-production environments (including but not limited to sandbox, testing, staging, training, or development environments).

Last Updated: July 2026

This Enterprise Support and Service Level Policy (“Policy”) describes the premium support and maintenance services (“Support Services”) provided by ThreatModeler for its subscribed products (“Product”). This Policy is incorporated by reference into the main agreement governing your use of the Product (“Agreement”). Capitalized terms not defined herein shall have the meaning set forth in the Agreement.

1. Definitions

  • "Authorized Contact" means a named individual designated by Customer in writing who is authorized to submit support tickets and communicate with ThreatModeler's support team.
  • "Business Day" means Monday through Friday, excluding public holidays in the primary support region.
  • "Business Hours" means 09:00 to 17:00 on Business Days in the single timezone designated in the applicable Order Form (the "Designated Timezone").
  • "Designated Timezone" means the specific timezone designated in the applicable Order Form. If no timezone is specified in the Order Form, the Designated Timezone shall default to Eastern Standard Time (EST) for North American agreements, or Central European Time (CET) for international agreements.
  • "Incident" means a failure of the Product to perform materially in accordance with its official Documentation.
  • "First Response Time" means the time elapsed from when Customer properly submits a support ticket to when a qualified ThreatModeler support engineer provides an initial diagnosis and confirms they have begun active investigation.
  • "Mitigation" means an action or workaround that reduces the business impact of an Incident.
  • "Resolution" means a permanent fix that resolves the root cause of an Incident.
  • "Service Level Objective (SLO)" means a non-binding target for service performance. ThreatModeler will use commercially reasonable efforts to meet SLOs, but they are not firm commitments subject to service credits.
  • "Support Portal" means ThreatModeler's primary support platform, currently located at https://support.threatmodeler.com.

2. Support Tiers, Channels, and Personnel

2.1. Support Tiers. Customer will receive Enterprise Support Services as specified in the applicable Order Form. ThreatModeler will provide Support Services under the following operational models:

(a) 24x5 Business Operations: Human support for general queries, configuration, and standard Incidents (High, Normal, and Low Severity) is provided strictly during local Business Hours in the Designated Timezone, Monday through Friday.
(b) 24x7 Urgent Coverage (System-Down Only): Automated escalation and on-call alerting for critical system-down events (Urgent Severity only) is provided 24 hours a day, 7 days a week, 365 days a year.

2.2. Support Channels. All support requests must be initiated via:
(a) The Support Portal (recommended); or
(b) Email to support@threatmodeler.com.
(c) Live chat functionality via the Support Portal, which ThreatModeler will use commercially reasonable efforts to make available during local Business Hours.

2.3. Authorized Contacts. Customer may designate up to eight (8) Authorized Contacts to interact with the support team.

2.4. Support Language. All Support Services, ticketing communications, documentation, and live interactions under this Policy are provided strictly and exclusively in the English language.

3. Incident Management & Service Levels

3.1. Incident Submission. To receive Support Services, an Authorized Contact must submit a support ticket through a designated Support Channel. The submission must include a suggested Severity Level and all information reasonably necessary for ThreatModeler to diagnose the Incident.

3.2. Severity Levels. ThreatModeler will categorize Incidents according to the definitions below. ThreatModeler reserves the right, acting reasonably and in consultation with Customer, to reclassify the severity level based on the demonstrable business impact.

SeverityDescription of Business Impact
UrgentThe production instance of the Product is completely unavailable, or a critical core functionality is unusable for all users, with no workaround available.
HighA critical Product functionality is unavailable or significantly degraded, severely impacting a majority of users or key business services, with no reasonable workaround available.
NormalOne or more non-critical features are not functioning correctly, or a major issue exists for which a reasonable workaround is available.
LowGeneral "how-to" questions, requests for information, configuration assistance, or non-critical issues with a minor impact on business operations.

3.3. Service Level Commitments and Objectives. ThreatModeler will use commercially reasonable efforts to meet the targets outlined below. First Response Time is a firm Service Level Agreement (SLA), while Mitigation and Resolution targets are Service Level Objectives (SLOs).

SeverityFirst Response Time (SLA)Next Response Target (SLO)Mitigation Target (SLO)Resolution Target (SLO)
Urgent4 Hours4 Hours8 Hours1 Business Day
High6 Hours4 Hours1 Business Day2 Business Days
Normal8 Hours8 HoursN/AN/A
Low12 Hours12 HoursN/AN/A

3.4. Post-Mitigation Commitment. Upon providing a Mitigation for an Urgent or High severity Incident, ThreatModeler commits to using commercially reasonable efforts to develop a permanent Resolution and will provide Customer with a plan for such Resolution upon request.

3.5. Pausing of Service Level Clock.

(a) ThreatModeler's time-based obligations under this Policy will be paused if ThreatModeler is awaiting a response or required information from Customer. The clock will resume once the dependency is resolved.

(b) If Customer fails to respond to a Support request or inquiry from ThreatModeler within five (5) consecutive Business Days, ThreatModeler reserves the right to close the support ticket automatically due to inactivity.

4. Uptime Commitment (Applicable to Cloud Deployments Only - Enterprise Tier)

4.1. Uptime SLA. ThreatModeler will use commercially reasonable efforts to make the Product available with a monthly Uptime Percentage of at least 99.9% (the "Uptime Commitment"). Uptime and availability shall be measured solely and exclusively using ThreatModeler's internal system logs and monitoring tools, which shall serve as the sole and final source of truth for any availability claims.

4.2. Definitions for Uptime.
"Downtime" means the total number of minutes during which the production instance of the Product's core login and modeling functionalities are completely unavailable to Customer. Downtime does not include partial degradations or any unavailability arising from Scheduled Maintenance or Excusable Downtime.
"Monthly Subscription Fee" means one-twelfth (1/12th) of the total annual subscription fees paid for the specific, affected Product, excluding any professional services, training, or taxes.
"Scheduled Maintenance" means planned maintenance announced at least 48 hours in advance. ThreatModeler will use commercially reasonable efforts to schedule such maintenance during non-peak hours (typically, weekend windows).
"Excusable Downtime" includes any unavailability resulting from: (a) a Force Majeure Event; (b) Customer's or its users' breach of the Agreement; (c) Customer's, its users', or local internet service providers' equipment, software, or network failures; (d) any performance degradation, congestion, or outage of the underlying third-party cloud infrastructure providers (including but not limited to AWS, Microsoft Azure, or Google Cloud) or global internet backbone carriers; or (e) malicious third-party acts, including DDoS attacks, not under ThreatModeler's direct control.

4.3. Service Credits and Uptime Thresholds. If the monthly Uptime Percentage falls below the Uptime Commitment, Customer may request a service credit ("Service Credit") calculated strictly as a percentage of the Monthly Subscription Fee as set forth below:

Monthly Uptime PercentageService Credit (% of Monthly Subscription Fee)
99.0% to 99.89%5%
Below 99.0%10%

4.4. Service Credit Procedures and Limitations.

(a) Sole and Exclusive Remedy. The Service Credits set forth in this Section 4 constitute Customer's sole and exclusive remedy, and ThreatModeler's sole liability, for any downtime, outages, service interruptions, or unavailability of the Product. Customer expressly waives any right to claim direct, indirect, consequential, or incidental damages for service unavailability.

(b) Claim Deadline. To receive a Service Credit, Customer must submit a written request via the Support Portal within fifteen (15) calendar days of the end of the calendar month in which the downtime occurred. Failure to submit the request within this timeframe shall constitute an irrevocable waiver of the right to receive such Service Credit.

(c) Cap and Exclusions. The total aggregate Service Credits issued under this Policy for any single calendar month shall be capped at thirty percent (30%) of the Monthly Subscription Fee. Service Credits have no cash value, are non-refundable, and can only be applied to future invoices. No Service Credits will be issued if Customer is past due on any payments or otherwise in breach of the Agreement.

5. Exclusions & Limitations

5.1. General Exclusions. Support Services do not cover problems arising from: (i) Customer's negligence or misuse of the Product; (ii) any third-party products not provided by ThreatModeler; (iii) use of the Product not in accordance with the Documentation; or (iv) any modification by anyone other than ThreatModeler.

5.2. Unsupported Versions. Support Services apply only to the current major version of the Product and the immediately preceding major version. ThreatModeler has no obligation to provide Support Services for older versions.

5.3. On-Premises and Non-Production Environments .

(a) For any Product deployed on-premise, the Mitigation Targets, Resolution Targets, and all Service Credits or Uptime Commitments under Section 4 of this Policy shall not apply.

(b) For the avoidance of doubt, the SLAs and SLOs specified in Section 3 of this Policy apply strictly to Customer's active production environments of the Product. ThreatModeler is not bound by any SLAs or SLOs for non-production environments (including but not limited to sandbox, testing, staging, training, or development environments).