Guardian Support

Engineers who run the platform, not a script that reads about it

Every Guardian support case is answered by an engineer with production access to the same telemetry you are looking at. No tier-one deflection layer, no copy-and-paste knowledge base replies, and a published escalation path you can invoke yourself.

Support plans

Three levels of coverage, one standard of engineer

Standard is included with Essentials, Premium with Professional and Signature with Enterprise. Sentinel Complete customers get Signature plus a Guardian SOC operating the tenant on their behalf. You can also buy up at any point in the term.

Included with Essentials

Standard

Business-hours coverage for teams whose estate can wait until Monday morning.

  • 8×5 coverage in your local business hours
  • Case submission via the console and by email
  • Four-hour Severity 1 response target
  • Full documentation, community and detection library access
  • Quarterly release notes and upgrade guidance
99.9% platform SLA
Included with Professional

Premium

Round-the-clock coverage with phone access and a monthly technical review.

  • 24×7×365 coverage, follow-the-sun across four SOCs
  • Console, email and direct phone case submission
  • One-hour Severity 1 response target
  • Monthly health check and tuning review with a support engineer
  • Two Guardian Certified Analyst seats each year
  • Priority access to pre-release detection content
99.95% platform SLA
Included with Enterprise

Signature

A named team that knows your architecture before you describe it.

  • Everything in Premium, plus a named technical account manager
  • Fifteen-minute Severity 1 response target, 24×7
  • Direct-to-engineer escalation without a triage queue
  • Quarterly business review and annual value assessment
  • Change advisory: pre-notification of every platform release
  • Six certification seats and an annual on-site workshop
99.99% platform SLA
Support is not a profit centre at Guardian There is no paid incident ticket, no per-case charge and no limit on how many cases you open. If you are opening a lot of them, that is our engineering problem to solve, and your case volume is reviewed by the product team every month.

Service levels

What each severity means, and what we commit to

Severity is set by impact, not by seniority of the person reporting it. If you and the engineer disagree on severity, the higher one applies until the case is understood.

Guardian severity definitions
Severity Definition Typical examples
Sev 1 · Critical Production security capability is unavailable or an attack is in progress and cannot be contained with the product as configured. Console unreachable in your region; sensors offline estate-wide; prevention failing open; suspected active compromise.
Sev 2 · High Major functionality is degraded or unavailable for a significant population, and no acceptable workaround exists. Detections not firing for one operating system family; response playbooks failing; a data connector silently dropping events.
Sev 3 · Medium Partial or intermittent impact with an available workaround, or a defect that does not affect protection. A report exporting incorrectly; an integration requiring manual re-auth; a console rendering issue.
Sev 4 · Low Questions, guidance, documentation gaps, configuration advice and feature requests. How to write a specific detection; sizing guidance; requesting a new API endpoint.
Response and update targets by support plan. Targets are measured from case creation to first human response.
Commitment Standard Premium Signature Complete
Coverage window 8×5 local24×7×36524×7×36524×7×365
Severity 1 first response 4 hours1 hour15 minutes3 minutes
Severity 2 first response 8 business hours2 hours1 hour15 minutes
Severity 3 first response 1 business day8 hours4 hours4 hours
Severity 4 first response 2 business days1 business day8 hours8 hours
Severity 1 update cadence Every 4 hoursEvery hourEvery 30 minutesContinuous
Phone case submission —IncludedIncludedIncluded
Named technical account manager ——IncludedIncluded
Direct-to-engineer escalation —On requestStandingStanding
Root cause analysis for Severity 1 On requestWithin 10 business daysWithin 5 business daysWithin 5 business days
Platform availability SLA 99.9%99.95%99.99%99.99%
Service credits for SLA miss YesYesYesYes

Scroll the table sideways to see all four plans.

Service credits are automatic — you do not need to claim them. Full definitions live in the Terms of Service, and plan entitlement is listed on the pricing page.

Opening a case

How to get a first-touch resolution

Cases that arrive with a diagnostic bundle and a precise time window are resolved on the first response 68 percent of the time. Cases that arrive with a screenshot are resolved on the first response 19 percent of the time. The difference is about ten minutes of your effort.

Open it in the console

Support → New case attaches your entitlement, tenant region, sensor versions and recent platform events automatically. Email to [email protected] works, but arrives without that context.

Set the severity honestly

Severity drives paging. A Severity 1 at 03:00 wakes an on-call engineer in your region. Use it when protection is genuinely impacted — and do use it when it is.

Attach the diagnostic bundle

Run gdn-support bundle on an affected sensor, or export the tenant diagnostic from the console. The bundle is redacted client-side before it leaves your network.

Watch it move

Every case has a public state machine: triaged, engineering, awaiting customer, resolved. You can escalate from inside the case at any point without asking permission.

case lifecycle / escalation path
STANDARD PATH Case created console, email or phone Triage within SLA target severity confirmed Support engineer reproduces and diagnoses Resolved with written cause Product engineering defect confirmed, fix scheduled ESCALATION PATHS You escalate button inside any case → duty manager SLA at risk automatic at 70% of target elapsed Severity 1 paging on-call engineering lead, immediate

What to include

  • A precise time window in UTC, including the first and last observed occurrence.
  • Affected asset identifiers — agent IDs or hostnames, not “a few laptops in finance”.
  • What changed immediately before: a policy edit, an upgrade, a network change, a new integration.
  • The diagnostic bundle from at least one affected sensor.
  • Business impact in one sentence — it drives severity more reliably than anything else.
Never attach credentials or live malware Do not paste API keys, tokens or passwords into a case. If a sample is needed, an engineer will provide a one-time upload link to the malware analysis environment. Any credential that reaches a case is rotated and the case is quarantined.
68% Cases resolved on the first human response when a diagnostic bundle is attached Rolling 12 months, all plans

Platform status

Availability we publish whether or not it flatters us

Guardian operates nineteen regional deployments. Availability, degradation and maintenance are posted publicly within five minutes of detection, and every incident gets a written post-mortem within five business days.

Availability, last 90 days — all regions All systems operational
90 days ago Today Operational — 86 days Degraded in one region — 3 days Maintenance — 1 day 99.993% aggregate availability across all nineteen regions

What the status page covers

  • Console, API, sensor check-in and detection pipeline, broken out per region
  • Scheduled maintenance, announced at least seven days in advance
  • Email, SMS, webhook and RSS subscriptions, filterable by region
  • Written post-mortems for every incident, kept permanently
Protection is local-first If the Guardian cloud becomes unreachable, sensors continue to prevent, detect and quarantine using local models, and buffer telemetry for up to 14 days. Availability incidents affect visibility, not protection.

Guardian Connect

Nineteen thousand practitioners, and Guardian engineers in the same channels

Guardian Connect is where customers publish detections, argue about tuning strategy and warn each other about tradecraft they are seeing before it reaches a report. Guardian product managers and Labs researchers participate under their real names, and community-contributed detection content that generalises is reviewed and shipped to every tenant with attribution.

  • Detection exchange — 3,100 community rules, each with a published false-positive profile.
  • Regional user groups in 22 cities, plus a quarterly virtual summit.
  • Product feedback that is triaged weekly by the team that owns the area, in public.
  • Open to everyone at your organisation, not just named contacts.
19k Members in Guardian Connect
3,100 Community-contributed detections
22 Cities with regional user groups
11 min Median time to a useful community answer

Training and certification

Two certification tracks, delivered live or self-paced, with lab environments that mirror a real estate under attack.

Guardian Certified Analyst (GCA)
Three days. Triage, investigation, hunting and response authoring. Assumes SOC experience but no Guardian experience.
Guardian Certified Engineer (GCE)
Four days. Deployment architecture, policy design, integration engineering and performance tuning at scale.
See training paths and dates
24 / 7 / 365

Emergency incident response hotline

If you believe you are compromised right now, do not open a support case and do not wait for a reply. Call the hotline. A Guardian incident responder — not a call handler — is on the line within fifteen minutes, and the first triage call is free whether or not you are a customer.

  • Ransomware, extortion, data theft, business email compromise, insider incidents and destructive attacks
  • Remote containment can begin during the first call for Guardian customers
  • Regulator-ready evidence handling and legal-privilege workflows from minute one

Global hotline

+1 (888) 555‑0117

North America. Regional numbers for EMEA, APJ and ANZ are listed on the contact page.


15 minResponder callback
47 minTo first containment
220+Responders worldwide

Need a higher level of coverage?

Support plans can be upgraded mid-term, and Guardian MDR can be attached to any Professional or Enterprise subscription. Your account team can quote both in a day.