Skip to main content

Vulnerability Response SLAs

Severity SLAs

SeveritySLADefault Action
Critical24 hoursBlock release and hotfix
High7 daysPrioritized sprint remediation
Medium30 daysPlanned remediation
Low90 daysBacklog with owner

Response Workflow

  1. Validate finding and affected assets.
  2. Classify severity and assign engineering owner.
  3. Apply containment if exploit risk is immediate.
  4. Patch, test, and verify in CI.
  5. Capture root cause and update guardrails/prompt templates.

Required Evidence

  • Scan report reference
  • PR or patch reference
  • Verification test evidence
  • Closure approval by security owner