Malware Protection From the Registry to the Developer Workstation
Learn More
Product
Platform Overview
Unified AppSec across AI, code, OSS & containers
Agents
Developer Tools
fREE
Integrations
AI Governance
AI Coding Agents
AI Models
MCP & Skills
AI Code
Code Scanning (AI SAST)
Secrets Detection
AI Security Review
Open Source
Dependencies (SCA)
Malicious Package Detection
Patches
Container Scanning
SBOM & Compliance
SUPPLY CHAIN
Package Firewall
CI/CD Security
Artifact Signing
Solutions
CATEGORY
AI Code Security
Software Supply Chain Security
Agentic Remediation
COMPLIANCE
Cyber Resilience Act (CRA)
FedRAMP
ISO 42001
PCI DSS
SOC 2
INDUSTRY
Financial Services
Software & Technology
Research
PROJECTS
Coding Agent Benchmark
OSS Risk Explorer
OWASP Top 10 Risks for OSS
RISK INTELLIGENCE
Vulnerability Reporting
Threat Research
Supply Chain Risk Hub
Research Hub
Latest research into vulnerabilities and software supply chain attacks.
Resources
LEARN
Docs
Blog
Case Studies
Events
Reports
COMPANY
Customers
Partners
Careers
News
About Us
Featured
Agent Security League
Agent Security League
Malware in Open Source Ecosystems
Malware in Open Source Ecosystems
Dependency Management ReportSecure Code Prompt Library
LeanAppSec
Docs
Pricing
Login
Book a Demo
Book Demo

Endor Labs Service Level Agreement (SLA)

Last updated on
September 28, 2026
Title goes here

Endor Labs Service Level Agreement (SLA)

Last updated on
September 28, 2026
Enter your email to be notified of changes to this list.

Capitalized terms used but not defined in this Service Level Agreement have the meanings given to them in the Endor Labs Master Services Terms or the Order Form that incorporates them by reference. The Uptime Commitment in this Exhibit B applies to the Endor Labs-hosted Services and does not apply to scans or software components running in Customer’s environment.

1. Uptime Commitment

Endor Labs will use commercially reasonable efforts to maintain a Monthly Uptime Percentage for the Services of at least 99.9%, calculated as ((Total Minutes in Month − Downtime) / Total Minutes in Month) × 100. “Downtime” means the total cumulative minutes per calendar month during which the Services are unavailable, excluding: (a) scheduled maintenance for which Endor Labs has given at least forty-eight (48) hours’ advance notice (Endor Labs will schedule maintenance during off-peak hours where practicable); (b) acts, omissions, equipment, software, systems, or networks of Customer or its Users (including anyone accessing the Services through Customer’s credentials), incompatibility of Customer’s environment with the Services, or Customer’s continued use of the Services after Endor Labs has advised Customer to modify its use; (c) outages, latency, rate limits, capacity constraints, suspensions, or other failures of third-party model, cloud, hosting, or infrastructure providers beyond Endor Labs’ reasonable control; (d) Force Majeure Events; (e) suspensions permitted under this Agreement; (f) Beta Features and Third-Party Services; or (g) the Internet generally or any systemic Internet failure or bandwidth limitation.

2. Service Credits

If the Monthly Uptime Percentage falls below 99.9% in any calendar month, Customer may request a service credit as set forth below:

Monthly Uptime Percentage Service Credit (% of monthly fee)
99.0% – < 99.9% 5%
95.0% – < 99.0% 10%
< 95.0% 15%

Service credits are Customer’s sole and exclusive remedy for any failure to meet the Uptime Commitment, are applied as a credit against future fees, are not redeemable for cash, and will not exceed 15% of the monthly fees for the affected month. To receive a credit, Customer must submit a written request within thirty (30) days after the end of the affected month. For purposes of these credits, “monthly fee” means one-twelfth of the annual fees for Customer’s Technical Success subscription under the applicable Order Form. Service credits are available only while Customer maintains an active subscription and is current on all undisputed amounts, and uptime is measured by Endor Labs’ monitoring systems, which measurements are conclusive absent manifest error.

3. Support

Endor Labs will provide support for the Services through Endor Labs’ designated support channels during Endor Labs’ standard support hours (9:00 a.m. to 5:00 p.m. Pacific time on weekdays, excluding U.S. federal holidays), as described in the Documentation or the applicable Order Form. Endor Labs will use commercially reasonable efforts to provide an initial response to support requests within the targets below, based on the severity level reasonably assigned by Endor Labs. Response targets are initial-response commitments, not resolution commitments, and apply during support hours.

Severity Level Description Initial Response Target
Severity 1 (Critical) A problem that severely impacts Customer’s use of the Services in a production environment, halting Customer’s business operations, with no procedural workaround available Four (4) business hours
Severity 2 (High) The Services are functioning but Customer’s use in a production environment is severely reduced, with a high impact on portions of Customer’s business operations and no procedural workaround available One (1) business day
Severity 3 (Medium) A partial, non-critical loss of use of the Services in a production environment; Customer’s business continues to function, including through a procedural workaround Two (2) business days
Severity 4 (Low) General usage questions, documentation errors, and feature or enhancement requests Five (5) business days
Gradient
Login
Endor Labs
Company
HomePricingContact UsAboutCareers
LEARN
BlogDocumentationeBook / ReportsEventsLeanAppSecSolution BriefVideo
Tools
Risk Explorer
Why Us?
vs Snykvs Semgrepvs Socketvs Traditional SCAvs Runtime SCA
Products
Use Cases
AI Apps
AI Code Governance
AI Static Application Security Testing (SAST)
Artifact Signing
Bazel Monorepos
CI/CD Discovery
Code Scanning
Compliance & SBOM
Container Scanning
Cyber Resilience Act
Digital Operational Resilience Act (DORA)
FedRAMP
GitHub Actions
ISO 42001
Malicious Package Detection
PCI DSS
RSPM
SBOM Ingestion
SCA with Reachability
Secrets Detection
SOC 2
Upgrades & Remediation
Integrations
Bazel
Bitbucket
C/C++
CircleCI
Claude
Cursor
Endor Labs with GitHub Advanced Security
Gemini
GitHub
GitHub Copilot
GitLab
Go
IDE
Java
JavaScript
Jenkins
Jira
Kotlin
Microsoft Defender for Cloud
.NET (C#)
PHP
Python
Ruby
Rust
Scala
Slack
Swift
TypeScript
Vanta
© 2026 Endor Labs. All rights reserved.
Legal and PrivacyTrust and Security

All names, logos, and brands of third parties listed on our site are trademarks of their respective owners. Endor Labs and its products and services are not endorsed by, sponsored by, or affiliated with these third parties. Our use of these names, logos, and brands is for identification purposes only, and does not imply any such endorsement, sponsorship, or affiliation.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.