Coverage
The Vijilan Security Operations Center operates 24 hours a day, every day of the year, including public holidays, staffed by analysts in the United States. Monitoring, triage and response are continuous; they are not a business-hours service with an out-of-hours pager.
Vijilan maintains SOC 2 Type II and ISO 27001 certification, independently audited. Current reports are available to partners under NDA through your account manager.
Severity levels and response targets
“Response” means the point at which a Vijilan analyst has taken ownership of the incident and begun work — not an automated acknowledgement. Targets are measured from the moment a detection is confirmed by our triage process, or from receipt of a partner-raised ticket, whichever is earlier.
| Severity | Typical scenario | Response target |
|---|---|---|
| P1 Critical | Confirmed active compromise — ransomware detonation, hands-on-keyboard intrusion, confirmed data exfiltration, domain-wide credential compromise. | 15 minutes |
| P2 High | Credible threat requiring urgent analyst judgement — successful phishing with credential entry, malware execution contained by tooling, privileged account anomaly. | 30 minutes |
| P3 Medium | Suspicious activity requiring investigation but no evidence of active compromise — policy violations, repeated failed authentication, unusual egress. | 4 business hours |
| P4 Low / informational | Tuning requests, reporting questions, informational detections, onboarding queries. | 1 business day |
Severity is assigned by the Vijilan SOC on the evidence available. A partner may request escalation at any time and we will re-assess immediately.
Response actions
Where your service tier and authorization permit it, Vijilan takes direct containment action rather than simply raising a ticket — disabling accounts, isolating hosts, blocking indicators — and then closes the loop with you. The specific actions we are permitted to take, and any that require your approval first, are set out during onboarding and recorded in your runbook. We do not take destructive or business-interrupting action outside that agreed scope without contacting you.
Exclusions
Response targets do not apply where:
- Required telemetry is not reaching us because a source system, agent or connector is down, misconfigured or has been changed without notice.
- A third-party platform we depend on is itself unavailable, including the client’s own EDR, identity or cloud provider.
- The environment is outside the agreed scope of monitoring.
- Scheduled maintenance has been notified in advance.
- Contact details you have given us are out of date and we cannot reach anyone.
- Events are outside our reasonable control, including force majeure.
Maintenance
Planned maintenance is scheduled outside peak hours wherever possible and notified in advance through partner channels. Monitoring and incident response continue throughout planned maintenance; portal or reporting availability may be briefly affected.
Service credits and claims
Remedies for a missed commitment, including any service credits and how they are calculated, are defined in your executed agreement with Vijilan rather than on this page, because they vary by tier and contract.
To raise a claim, contact your account manager or legal@vijilan.com within 30 days of the incident, with the ticket reference and the commitment you believe was missed. We will investigate against our own timestamped SOC records and respond with findings.
Reporting and review
Partners receive regular reporting on detections, response actions and SLA attainment. Performance against these targets is reviewed with you on the cadence set out in your agreement. If you believe our numbers are wrong, ask — the underlying case records are available to you.
Questions
Commercial and contractual questions: legal@vijilan.com. Live incidents always go to the SOC, not to email — see the incident response hotline.