Skip to main content

Support

Where to send incidents and data requests, and what to expect in return. We tell you the truth about our response posture — this page never promises a service level we have not committed to in writing.

Contact support

Reach the support team by email. Include your company name, what you were doing, and the correlation id from the affected screen so we can trace it end to end.

Support email
support@ulpi.io
Security and abuse
security@ulpi.io

Include in every report

  • The correlation id shown on the affected screen.
  • Your company name and the account email you signed in with.
  • When it happened and what you expected versus what you saw.

If a support contact is not configured for this deployment, launch readiness stays red until one is set — an operator cannot ship without a reachable support path.

Severity expectations

Severity sets our triage order, not a contractual deadline. We acknowledge during support hours and work the highest severity first. Any guaranteed response or resolution time lives only in a signed agreement.

  • Sev 1 — Critical

    Examples: The platform is down, data is at risk, or a security incident is suspected.

    Response posture: Acknowledged first, worked continuously during support hours until contained; escalated to on-call.

  • Sev 2 — High

    Examples: A core flow is broken with no workaround, blocking a company from operating.

    Response posture: Acknowledged during support hours and prioritized ahead of routine work.

  • Sev 3 — Normal

    Examples: A non-blocking defect, a question, or a request with a workaround.

    Response posture: Acknowledged during support hours and scheduled into the normal queue.

These are target response postures during support hours, not a guaranteed SLA. A binding SLA exists only where we have signed one with you.

Export and deletion requests

Owners can export or delete a company's data directly. Both are owner-only, irreversible trust affordances; deletion crypto-shreds the company key so the data cannot be resurrected.

Request a data export

Owners request a full Tier-1 export from the data controls page. The export produces a signed, expiring download link.

Request a deletion

Owners delete a company from the same data controls page. Deletion is permanent and is confirmed once the company key is shredded.

Open data export and deletion controls

If you are not an owner, ask an owner on your team to perform the request, or email support with your company name and the action you need.

Incident escalation

Suspected security or cross-tenant incidents go to the security address immediately. Incidents are tracked against an explicit incident ledger — an incident is open until it is resolved with evidence, never assumed resolved by silence.

  1. Email the security address with the correlation id, what you observed, and the time it happened.
  2. We acknowledge, open an incident ledger entry, and assign an on-call owner.
  3. We contain, record the evidence required for the entry, and keep you updated until it is resolved.

Provider escalation

If the incident involves a model or runner provider, we escalate to that provider's support channel in parallel. Provider escalation links are kept in the support runbook so on-call can reach the right provider fast.

On-call owner, required incident evidence, the response workflow, and provider escalation links live in the support runbook (ops/launch/support-runbook.md).