Skip to content

Documentation

Support Policy

Support channels, severity levels, response targets, and incident communication.

RuntraceLast updated July 24, 2026

Scope

This policy describes the standard support provided with hosted Runtrace Business. Enterprise order forms may add named contacts, shorter response targets, service credits, maintenance terms, or private deployment procedures.

Contacting support

Support and billing requests may be sent to sales@runtrace.co.

Include the organization name and the relevant device, finding, report, or scan request identifier. Do not send secret values, private keys, source files, screenshots, shell history, or developer document contents.

Severity and response targets

  • P0: the hosted service is unavailable or a confirmed security incident is actively affecting customer data. Business initial response target: one business day.
  • P1: enrollment, authentication, scanning, or reporting is materially impaired for multiple devices. Business initial response target: two business days.
  • P2: product questions, report interpretation, policy tuning, false-positive review, or a limited product defect. Business initial response target: five business days.
  • Response targets are measured on business days and are support goals, not contractual service levels or service credits. Enterprise commitments apply only when stated in an order form.

Incident communication

Runtrace investigates confirmed service and data-security incidents, identifies the affected scope, and communicates known customer impact and mitigation status. Material service incidents and planned maintenance are published on the status page. Customers affected by a confirmed personal-data breach are notified without undue delay.

Maintenance and releases

Runtrace tests product changes before release and maintains audit history for security-sensitive administrative actions. macOS agent packages distributed to customers are signed and notarized. Planned maintenance that materially affects availability is communicated through the status page.

Customer controls

Authorized administrators can review scan history, manage finding status and exceptions, download reports and audit history, export organization data, deactivate devices, and request account deletion according to the retention policy.