Support
Product support goes to hello@vulnify.io. A security issue goes to the vulnerability disclosure policy, not to that inbox. This page states the hours and the first-response targets. The targets are not a contractual SLA, and they are not a time to fix the issue.
The Terms of Service say the service is in early access and that any uptime commitment is a separate written SLA. This page is not that document.
Channels
Section titled “Channels”| Topic | Where to write |
|---|---|
| Product support, billing, and how the API or an SDK behaves | hello@vulnify.io |
| A vulnerability in Vulnify | Vulnerability disclosure |
Do not send exploit details, credentials, or proof-of-concept code to hello@. Follow the disclosure policy for that. There is no support@ address. hello@ is the support channel.
Support hours are Monday to Friday, 09:00–17:00 in America/Sao_Paulo (BRT). That is eight hours a day, five days a week. The same window applies on every plan, including Enterprise.
A message that arrives outside that window counts as received at 09:00 on the next weekday in that timezone. The clock for a target runs only inside the window.
Severities
Section titled “Severities”| Id | Use it when |
|---|---|
| S1 | The production API is not serving LIVE decisions. For example, POST /v1/events returns HTTP 5xx for keys that were working, or GET /health/ready reports the API is not ready and live traffic cannot get a decision. |
| S2 | A major path is broken and there is no workaround. Examples: webhook deliveries stop, reviews are not created, or an HTTP or MCP gateway route does not forward a call the decision allowed. |
| S3 | Behavior is degraded and a workaround exists, or an SDK or docs defect does not stop decisions. |
| S4 | A how-to question, an account or billing request, or a feature request. |
Put the severity in the subject, for example S2 webhook deliveries stopped. Vulnify may reclassify the report after reading it.
Response targets by plan
Section titled “Response targets by plan”The time below is the target for a first reply from a person. It is not a resolution time. It does not add a credit, a penalty, or a term to the contract. Plan names match Plans.
| Severity | Developer | Team | Business | Enterprise |
|---|---|---|---|---|
| S1 | 1 business day | 8 business hours | 4 business hours | 2 business hours |
| S2 | 2 business days | 1 business day | 8 business hours | 4 business hours |
| S3 | 5 business days | 3 business days | 2 business days | 1 business day |
| S4 | No timed target | 5 business days | 3 business days | 2 business days |
A business hour is one hour inside the window above. A business day is that full window (eight hours). “No timed target” on Developer S4 means the message is read in the same hours and answered when someone can, without a clock.
What to include
Section titled “What to include”- The request id from the
X-Request-Idresponse header. The API keeps a plain id you send on the request and returns it on the response. See Authentication. - The SDK name and version. For Node.js that is
@vulnify/sdkand the version you installed. For Python that is thevulnifypackage and its version. If you called the HTTP API directly, say so, and includex-vulnify-versionfrom the response when you have it. - Timestamps in UTC for when you sent the call and when you noticed the problem.
Also include the plan, whether the key was LIVE or TEST, and the endpoint or SDK method. Say what you expected and what happened.
Do not include API keys, webhook secrets, passwords, or the contents of customer records. See Security and compliance.
Status and changelog
Section titled “Status and changelog”Current API readiness is GET /health/ready. "ready": true means the process can serve traffic at the time of that request. The endpoint is not an incident history.
Changes to the public contract and to these docs are in the Changelog.

