Skip to main content

SLA Policy

Path: /admin/sla · Sidebar: Administration → SLA Policy

SLA policy defines how long you have to remediate a finding based on its severity. These deadlines drive the SLA-breached KPIs and the remediation reports.

Configure SLAs

Set a remediation window per severity, for example:

SeverityExample SLA
Critical7 days
High30 days
Medium90 days
Low180 days

You can vary SLAs by environment/criticality so production-critical apps get tighter deadlines.

How SLAs are used

  • Each vulnerability gets a due date = discovery date + SLA window.
  • SLA-breached counts appear on the Dashboard and Priorities.
  • The Remediation & SLA report tracks overdue items and MTTR by team.
Make SLAs achievable

SLAs only help if teams can meet them. Set windows your teams can realistically hit, then tighten as MTTR improves - perpetually-breached SLAs lose their meaning.