Support & SLA
Company overview, service description, support model, and SLA commitments.
Company Overview
| Legal entity | Aurea, Inc. |
| Product | CloudFix — automated AWS cost optimisation platform |
| Headquarters | United States |
| Platform hosting | Amazon Web Services, us-east-1 (N. Virginia) |
| AWS partner status | ISV Accelerate Partner · Cloud Operations Competency (Cost Management) |
| Certifications | SOC 2 Type 2 · FinOps Certified Platform |
| AWS Marketplace | View CloudFix on AWS Marketplace → |
Service Description
CloudFix is a SaaS platform that automatically identifies and implements AWS cost optimisation opportunities across your AWS estate. It operates via a secure read-oriented IAM role model deployed into your AWS account via CloudFormation StackSet — no agents, no third-party software, only AWS-native services.
Finders
75+ automated analysers scan your AWS account metadata — Cost & Usage Reports, CloudWatch metrics, resource configuration — to identify cost savings opportunities across 30+ AWS services.
Fixers
For each opportunity you choose to act on, CloudFix generates a change template through AWS Systems Manager. Changes execute only after your explicit approval — never automatically.
RightSpend
An optional module for Reserved Instance and Savings Plan management, providing automated purchase recommendations and RI conversion optimisation.
API & Integrations
A REST API and outbound webhook capability enable integration with ITSM and service desk platforms, allowing recommendations to flow through existing approval workflows.
What CloudFix accesses in your AWS account
- AWS Cost and Usage Reports (CUR) — billing and usage metadata only
- CloudWatch metrics — performance and utilisation data for optimisation analysis
- CloudTrail logs — read access for audit and recommendation context
- Resource metadata via Describe/List/Get API calls — no access to application data, S3 object contents, or database records
Support Model
Support Channels
| Channel | Purpose | Availability |
|---|---|---|
| Support portal | Primary channel for all support requests, product questions, and incident reporting. Powered by Kayako. | support.cloudfix.com |
| Trust Center contact form | Security concerns, compliance queries, documentation requests, vulnerability reports. | trust.cloudfix.com/contact |
| In-app support | Contextual help and ticket submission from within the CloudFix dashboard. | Available when logged in |
Support Coverage
CloudFix provides support during standard business hours (09:00–18:00 ET, Monday–Friday). Critical incidents (P1) are monitored outside business hours with on-call escalation.
Service Level Commitments
Platform Availability
- CloudFix Dashboard: 99.9% uptime target (measured monthly, excluding maintenance windows)
- API: 99.9% uptime target
- Scheduled maintenance: Communicated at least 72 hours in advance; typically performed 02:00–04:00 UTC
- Exclusions: AWS infrastructure incidents, force majeure, customer-caused outages
Incident Response SLA
| Priority | Definition | Initial response | Resolution target |
|---|---|---|---|
| P1 — Critical | Platform completely unavailable or data integrity risk; no workaround | 1 hour | 4 hours |
| P2 — High | Significant feature impairment; partial workaround available | 4 business hours | 2 business days |
| P3 — Medium | Non-critical issue; workaround available | 1 business day | 5 business days |
| P4 — Low | General questions, feature requests, documentation queries | 2 business days | Best efforts |
Business hours: 09:00–18:00 ET, Monday–Friday, excluding US public holidays. P1 incidents are monitored on-call outside business hours.
Escalation Path
| Level | Contact | Trigger |
|---|---|---|
| Level 1 | CloudFix support team via support.cloudfix.com | All initial requests |
| Level 2 | Senior support engineer (auto-escalated for P1/P2 after initial response SLA) | P1 unresolved > 2 hours · P2 unresolved > 1 business day |
| Level 3 | Engineering team lead | P1 unresolved > 4 hours · complex technical issues requiring engineering involvement |
| Security escalation | Security team via Trust Center contact form | Any security incident or vulnerability report |
Incident Management
CloudFix follows a structured incident management process aligned with SOC 2 requirements.
Incidents are detected via automated monitoring alerts, customer reports, or internal escalation. On detection, an incident commander is assigned and the incident is classified P1–P4 based on impact and scope.
- Service incidents (P1/P2): Status page updated within 30 minutes of confirmed incident. Affected customers notified via in-app notification and/or email.
- Security incidents: Affected customers notified within 24 hours of confirmed security incident, regardless of severity.
- Data breaches: Notification within 72 hours as required by applicable regulations, with full incident details provided as they become available.
Following resolution of P1/P2 incidents, a post-incident review (PIR) is conducted within 5 business days. The PIR documents root cause, contributing factors, timeline, and corrective actions. Summaries are available to customers on request.
All production changes follow a defined change management process: peer review, staging environment testing, and phased rollout. Emergency changes require post-implementation review. Scheduled maintenance is communicated at least 72 hours in advance via the status page.
Vulnerability Management
Internal Programme
- Regular third-party penetration testing — results available under NDA (request via Compliance page)
- Continuous automated dependency scanning for known CVEs
- Internal security assessments aligned with SOC 2 requirements
- Patch management policy: critical CVEs remediated within 30 days of disclosure; high within 60 days
Responsible Disclosure
CloudFix operates a responsible disclosure programme. If you believe you have identified a security vulnerability:
- Submit details via the Trust Center contact form, selecting Vulnerability Report as the subject.
- Include a clear description of the vulnerability, steps to reproduce, and potential impact.
- CloudFix will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.
- We request a 90-day disclosure window from initial report to allow for remediation before any public disclosure.
- Coordinated disclosure is welcomed — we will keep you informed of remediation progress and notify you when a fix is deployed.