Clear on who moves.
Two tiers. Not five. A tier we cannot honour is just a promise on paper.
Hours that are actually covered
Not a promise, a calendar. A filled cell means someone is bound to a response target.
Standard
45 hours, weekdays 09:00–18:00 WIB MON TUE WED THU FRI SAT SUN
0006121824
Critical
168 hours, all day every day MON TUE WED THU FRI SAT SUN
0006121824
Standard and Critical
| Standard | Critical | |
|---|---|---|
| Service hours | Mon–Fri, 09:00–18:00 WIB | Every day, around the clock |
| Initial response target | Next business day | Within hours, nights and holidays included |
| Channels | Email and WhatsApp | Email, WhatsApp and an escalation phone line |
| Configuration changes | Scheduled | Scheduled and emergency |
| Updates within the version | You run them, we stand by | You run them, or we do |
| Major version moves | Scheduled together | Scheduled together, outside peak hours |
| Incident investigation | Within service hours | Whenever the incident happens |
| Included tickets | 12 per year | By request |
| Replacement unit | Per delivery model | Per delivery model, first in line |
| Review cadence | Yearly | Quarterly, with written notes |
Device count, number of sites and compliance obligations set the final price. That is what the assessment maps out.
How we count
- Response time
- Counted until a human states they are on it. Not until an auto-reply lands.
- Resolution time
- Never promised as a fixed number. Hardware failure, ISP trouble and a bad config each recover on a different path.
- Outside service hours
- Standard tier reports outside working hours are logged and queued for the next business day. Critical has no queue.
- What uses a ticket
- Questions, guidance and configuration advice your team carries out are unlimited within service hours and use nothing. A ticket is only counted when the work has to be done hands-on by us. Additional tickets are available in blocks.
- Out of scope
- ISP links, site power and third-party gear still get our help tracing. What carries no response target is what sits outside our control.
Deployment & migration
Not everyone is ready to sign an annual contract on day one. This is the way in.
Included
- Segmentation and firewall rule design based on what you actually run
- Staged migration off the old device inside agreed change windows
- Site-to-site and remote user VPN configuration
- Failover tested before we call it done
- Handover documentation: diagrams, addressing, rules and the reasoning behind them
- Hands-on time with your team after cutover
Not included
- Hardware procurement
- Cabling and on-site works
- Ongoing monitoring after handover
- Configuration changes once the hands-on period ends
Whose hardware it runs on
| SG on Your Hardware | SG in a Box | SG as a Service | |
|---|---|---|---|
| Availability | Available | Coming soon | Coming soon |
| Hardware | Yours | From us | Not needed |
| Hardware warranty | From your vendor | One year, unit replaced | Not applicable |
| Software & configuration | Us | Us | Us |
| Security updates | We stand by | We stand by | We run them |
| Replacement on failure | You supply | We supply | Not applicable |
| Cost model | One-time | One-time | Monthly subscription |
| Service hours & SLA | Per tier | Per tier | Per tier |
Which tier fits?
Usually clear inside thirty minutes. Start there.