Service commitments

We commit to the number, not to the uptime.

Version 21 September 2026. What you are buying here is a number you can make a decision on. A portal that runs at 99.99% and returns a wrong number is worse than a portal that takes an afternoon off. So the commitments below are ordered accordingly.


A. Measurement integrity

These four are enforced in the software. They are not undertakings we remember to honour; they are gates that run on every job.

A1. We never call something we could not measure a gap in your monitoring

“No alert” is not a measurement. It is three possibilities wearing one number:

  1. the monitoring did not catch it — only this one is a gap in your posture
  2. the monitoring received nothing to catch — a broken log pipeline
  3. the attack never reached the sensor

Before concluding “missed”, the software must prove the log pipeline was alive inside the measurement window. If it cannot, the cell is labelled UNMEASURED with the reason printed verbatim, and it is excluded from your gap list, from the coverage denominator, from any remediation proposal, and from the invoice.

A2. We say whose monitoring was measured

Every coverage figure carries one of three labels, printed next to the number:

We do not add those three together into one figure.

A3. Every “detected” claim comes with evidence you can check yourself

Each detected cell carries the rule ID and the measured detection time. You open your own monitoring and look it up. We do not print a coverage figure without saying where it came from.

A4. We publish our own error bars, and our corrections

We ran both of our measurement modes against the same twin, compared them cell by cell, and published the result — including a correction to our own sales material when a later review showed one of our figures was wrong. If we later find that something we already delivered to you was wrong, we tell you before you ask, and we say which cells it affects.

A5. We do not bill a measurement that could not measure

Each run records the number of techniques actually measurable. If none were, the run is marked non-billable with the reason attached. You can read that ledger at any time.


B. Turnaround

Business days, Monday to Friday, Vietnamese public holidays excluded.

Acknowledge receipt of your infrastructure file
1 business day
Report a format problem, naming the exact line or field
1 business day
Deliver the first measurement report from a valid file
5 business days
Re-measure after you apply detection content
3 business days
Answer a technical question
1 business day
Correct a delivered result found to be wrong
2 business days from discovery
Delete your data on request, with written confirmation
3 business days

If we are going to be late, we tell you before the deadline, with the reason and a new date. Late by more than double the commitment without prior notice, and that measurement is free.


C. Availability — stated plainly


D. Where this service is weak

Listed up front so you do not have to discover it after paying.

  1. A finite technique set. We measure against a specific list of ATT&CK techniques, enumerated in the report. Outside that list we make no claim at all.
  2. A replica is not the original. In the default mode the result describes a stack as you declared it. However far the declaration is from reality, the result is that far off.
  3. Detection content needs review before use. What we hand you contains rules verified to fire on a live SIEM and rules not yet verified — labelled differently. The second kind needs your review before it goes near production. And not every gap we find has a rule behind it; where there is none, we say so rather than inventing one.
  4. We are a small team. That limits how much we take on at once. We will say so before accepting work, rather than accepting it and running late.

Questions: dongnx@atkvn.com · Terms of service · Prepare your infrastructure file