Service level agreement
Scope
This Service Level Agreement (SLA) defines our reaction and solution times for functional bugs and security vulnerabilities, the soft availability target for our Cloud apps, and how we approach compatibility with new Confluence versions. It is incorporated into our End User License Agreement as a Provider-Specific Term and applies to paid apps as a contractual commitment; the corresponding statements for free apps are best-effort only.
Cloud Service availability
We target a soft availability of 99.5% per calendar month for our Cloud apps, measured at the application endpoint we operate. This is a best-effort target without service credits or financial remedies.
The following are excluded from availability measurement:
Incidents in upstream platforms outside our control (Atlassian Cloud, AWS, Heroku, Forge runtime, network providers).
Scheduled maintenance announced at least 48 hours in advance.
Emergency maintenance to address a security or stability risk, where reasonable notice is given.
Force majeure events as defined in our EULA.
Customer-side issues, including misconfiguration, integrations with third-party systems, and end-of-life Confluence or browser versions.
Data Center apps are installed and operated by the customer in the customer's environment; availability of Data Center apps is the customer's responsibility.
Expected reaction and solution time related to bugs
Functional bugs
Severity | Reaction time (paid) | Solution time* (paid) | Reaction time (free) | Solution time* (free) |
|---|---|---|---|---|
Critical | 2 days | 5 days | 3 days | 7 days |
Major | 2 days | 5 days | 3 days | 7 days |
Minor | 3 days | 10 days | 4 days | 15 days |
Trivial | 3 days | 15 days | 4 days | 20 days |
Security vulnerabilities
Severity follows CVSS v3.1 base score:
CVSS v3.1 base score | Industry label | Reaction time (paid & free) | Solution time* (paid) | Solution time* (free) |
|---|---|---|---|---|
9.0 – 10.0 | Critical | 1 business day | 5 days | 7 days |
7.0 – 8.9 | High | 2 business days | 10 days | 15 days |
4.0 – 6.9 | Medium | 3 business days | 15 days | 20 days |
0.1 – 3.9 | Low | 5 business days | next regular release | next regular release |
*) We can only commit a solution time for issues under our control. Issues caused by the host platform (Confluence, Jira, Forge, Atlassian APIs) or third-party dependencies have no committed solution time; we will track and escalate the upstream ticket. An acceptable workaround counts as a solution.
**) "Days" means business days, defined as Monday through Friday, 09:00–17:00 Europe/Berlin (CET/CEST), excluding public holidays in Bavaria, Germany and the period from 24 December to 1 January inclusive. Where a clock would start outside business hours, it starts at the beginning of the next business day.
Back port policy of security related bugs
We ensure that we fix all versions of our app to cover all Confluence versions currently supported by Atlassian.
How to report and when reaction time starts
All bug reports and security disclosures must be submitted via one of the following channels:
Service Desk (preferred): https://purde-software.atlassian.net/servicedesk/customer/portal/2
Email: support@purde.de
Security vulnerabilities: as described in our Vulnerability Disclosure process (once published; until then, use the channels above and mark the report as security-sensitive)
Reaction time starts when a report is received via one of these channels during business hours. Reports received outside business hours are treated as received at the start of the next business day. Communication via other channels (LinkedIn, social media, direct messages, etc.) is not in scope of this SLA.
What is not covered
The reaction and solution times in this SLA do not apply to:
Bugs caused by, or only reproducible in, end-of-life versions of Confluence or other host products no longer supported by Atlassian.
Bugs caused by third-party apps, customizations, or modifications outside our control.
Bugs originating in the host platform (Confluence, Jira, Forge, Atlassian APIs) for which a workaround is not within our reach. We will report these to Atlassian and track the upstream ticket.
Customer environments that do not meet the documented system requirements.
Free apps, where commitments in this SLA are best-effort and non-contractual.
Solution time of feature requests
We will respond to feature requests within the general reaction time indicated before and will indicate how we will proceed with the feature request. However we can’t make any general statements if and if yes in which time a new feature will be implemented.
Compatibility with new Confluence versions
We target compatibility with new minor and patch Confluence versions within 10 business days after their general availability, and with new major versions (which typically introduce breaking changes, e.g. Confluence 8 → 9) within 20 business days. These targets apply to Data Center apps; Cloud apps follow Atlassian's platform release cadence and we maintain compatibility on a continuous basis.
Definitions
Term | Definition |
|---|---|
Critical bug | The whole app cannot be used; no workaround. |
Major bug | Major functionality is unusable; the intended use cannot be achieved without significant effort. |
Minor bug | Non-major functions are unusable, or there are notable usability issues; a workaround exists. |
Trivial bug | All other defects, including cosmetic issues. |
Reaction time | Time from receipt of a valid report (per "How to report") until the first qualified action to investigate, acknowledged to the reporter. |
Solution time | Time from receipt of a valid report until a fix or acceptable workaround is delivered. |
Best effort | A target we work toward in good faith but for which we do not commit a contractual remedy or service credit. |