Skip to content

Support

Product support goes to hello@vulnify.io. A security issue goes to the vulnerability disclosure policy, not to that inbox. This page states the hours and the first-response targets. The targets are not a contractual SLA, and they are not a time to fix the issue.

The Terms of Service say the service is in early access and that any uptime commitment is a separate written SLA. This page is not that document.

Topic Where to write
Product support, billing, and how the API or an SDK behaves hello@vulnify.io
A vulnerability in Vulnify Vulnerability disclosure

Do not send exploit details, credentials, or proof-of-concept code to hello@. Follow the disclosure policy for that. There is no support@ address. hello@ is the support channel.

Support hours are Monday to Friday, 09:00–17:00 in America/Sao_Paulo (BRT). That is eight hours a day, five days a week. The same window applies on every plan, including Enterprise.

A message that arrives outside that window counts as received at 09:00 on the next weekday in that timezone. The clock for a target runs only inside the window.

Id Use it when
S1 The production API is not serving LIVE decisions. For example, POST /v1/events returns HTTP 5xx for keys that were working, or GET /health/ready reports the API is not ready and live traffic cannot get a decision.
S2 A major path is broken and there is no workaround. Examples: webhook deliveries stop, reviews are not created, or an HTTP or MCP gateway route does not forward a call the decision allowed.
S3 Behavior is degraded and a workaround exists, or an SDK or docs defect does not stop decisions.
S4 A how-to question, an account or billing request, or a feature request.

Put the severity in the subject, for example S2 webhook deliveries stopped. Vulnify may reclassify the report after reading it.

The time below is the target for a first reply from a person. It is not a resolution time. It does not add a credit, a penalty, or a term to the contract. Plan names match Plans.

Severity Developer Team Business Enterprise
S1 1 business day 8 business hours 4 business hours 2 business hours
S2 2 business days 1 business day 8 business hours 4 business hours
S3 5 business days 3 business days 2 business days 1 business day
S4 No timed target 5 business days 3 business days 2 business days

A business hour is one hour inside the window above. A business day is that full window (eight hours). “No timed target” on Developer S4 means the message is read in the same hours and answered when someone can, without a clock.

  • The request id from the X-Request-Id response header. The API keeps a plain id you send on the request and returns it on the response. See Authentication.
  • The SDK name and version. For Node.js that is @vulnify/sdk and the version you installed. For Python that is the vulnify package and its version. If you called the HTTP API directly, say so, and include x-vulnify-version from the response when you have it.
  • Timestamps in UTC for when you sent the call and when you noticed the problem.

Also include the plan, whether the key was LIVE or TEST, and the endpoint or SDK method. Say what you expected and what happened.

Do not include API keys, webhook secrets, passwords, or the contents of customer records. See Security and compliance.

Current API readiness is GET /health/ready. "ready": true means the process can serve traffic at the time of that request. The endpoint is not an incident history.

Changes to the public contract and to these docs are in the Changelog.