Service level agreement

Service level agreement

Scope

This Service Level Agreement (SLA) defines our reaction and solution times for functional bugs and security vulnerabilities, the soft availability target for our Cloud apps, and how we approach compatibility with new Confluence versions. It is incorporated into our End User License Agreement as a Provider-Specific Term and applies to paid apps as a contractual commitment; the corresponding statements for free apps are best-effort only.

Cloud Service availability

We target a soft availability of 99.5% per calendar month for our Cloud apps, measured at the application endpoint we operate. This is a best-effort target without service credits or financial remedies.

The following are excluded from availability measurement:

  • Incidents in upstream platforms outside our control (Atlassian Cloud, AWS, Heroku, Forge runtime, network providers).

  • Scheduled maintenance announced at least 48 hours in advance.

  • Emergency maintenance to address a security or stability risk, where reasonable notice is given.

  • Force majeure events as defined in our EULA.

  • Customer-side issues, including misconfiguration, integrations with third-party systems, and end-of-life Confluence or browser versions.

Data Center apps are installed and operated by the customer in the customer's environment; availability of Data Center apps is the customer's responsibility.

Expected reaction and solution time related to bugs

Functional bugs

Severity

Reaction time (paid)

Solution time* (paid)

Reaction time (free)

Solution time* (free)

Severity

Reaction time (paid)

Solution time* (paid)

Reaction time (free)

Solution time* (free)

Critical

2 days

5 days

3 days

7 days

Major

2 days

5 days

3 days

7 days

Minor

3 days

10 days

4 days

15 days

Trivial

3 days

15 days

4 days

20 days

Security vulnerabilities

Severity follows CVSS v3.1 base score:

CVSS v3.1 base score

Industry label

Reaction time (paid & free)

Solution time* (paid)

Solution time* (free)

CVSS v3.1 base score

Industry label

Reaction time (paid & free)

Solution time* (paid)

Solution time* (free)

9.0 – 10.0

Critical

1 business day

5 days

7 days

7.0 – 8.9

High

2 business days

10 days

15 days

4.0 – 6.9

Medium

3 business days

15 days

20 days

0.1 – 3.9

Low

5 business days

next regular release

next regular release

*) We can only commit a solution time for issues under our control. Issues caused by the host platform (Confluence, Jira, Forge, Atlassian APIs) or third-party dependencies have no committed solution time; we will track and escalate the upstream ticket. An acceptable workaround counts as a solution.

**) "Days" means business days, defined as Monday through Friday, 09:00–17:00 Europe/Berlin (CET/CEST), excluding public holidays in Bavaria, Germany and the period from 24 December to 1 January inclusive. Where a clock would start outside business hours, it starts at the beginning of the next business day.

Back port policy of security related bugs

We ensure that we fix all versions of our app to cover all Confluence versions currently supported by Atlassian.

How to report and when reaction time starts

All bug reports and security disclosures must be submitted via one of the following channels:

Reaction time starts when a report is received via one of these channels during business hours. Reports received outside business hours are treated as received at the start of the next business day. Communication via other channels (LinkedIn, social media, direct messages, etc.) is not in scope of this SLA.

What is not covered

The reaction and solution times in this SLA do not apply to:

  • Bugs caused by, or only reproducible in, end-of-life versions of Confluence or other host products no longer supported by Atlassian.

  • Bugs caused by third-party apps, customizations, or modifications outside our control.

  • Bugs originating in the host platform (Confluence, Jira, Forge, Atlassian APIs) for which a workaround is not within our reach. We will report these to Atlassian and track the upstream ticket.

  • Customer environments that do not meet the documented system requirements.

  • Free apps, where commitments in this SLA are best-effort and non-contractual.

Solution time of feature requests

We will respond to feature requests within the general reaction time indicated before and will indicate how we will proceed with the feature request. However we can’t make any general statements if and if yes in which time a new feature will be implemented.

Compatibility with new Confluence versions

We target compatibility with new minor and patch Confluence versions within 10 business days after their general availability, and with new major versions (which typically introduce breaking changes, e.g. Confluence 8 → 9) within 20 business days. These targets apply to Data Center apps; Cloud apps follow Atlassian's platform release cadence and we maintain compatibility on a continuous basis.

Definitions

Term

Definition

Term

Definition

Critical bug

The whole app cannot be used; no workaround.

Major bug

Major functionality is unusable; the intended use cannot be achieved without significant effort.

Minor bug

Non-major functions are unusable, or there are notable usability issues; a workaround exists.

Trivial bug

All other defects, including cosmetic issues.

Reaction time

Time from receipt of a valid report (per "How to report") until the first qualified action to investigate, acknowledged to the reporter.

Solution time

Time from receipt of a valid report until a fix or acceptable workaround is delivered.

Best effort

A target we work toward in good faith but for which we do not commit a contractual remedy or service credit.