We run your firm’s instance, keep it current, back it up on a schedule and answer support requests within defined times. You keep control of your people, your data and your professional obligations. If you leave, you leave with a full export.
1. Scope of the managed service
In a managed deployment we operate the firm’s instance set on your behalf: hosting, routine maintenance, software updates, monitoring, scheduled backups and support. Your firm keeps administration of its own users, permissions, procedures, data and settings.
Unless stated otherwise, we operate in our own environment. Bring-your-own-account deployments are governed by the same service levels, except where the underlying platform is under your account and outside our control — those areas are marked in the responsibility matrix below.
2. Service levels
| Commitment | Target | How it is measured |
|---|---|---|
| Monthly availability | 99.9% of requests served successfully | Measured monthly, excluding scheduled maintenance and events outside our control |
| Scheduled maintenance | Announced at least 3 business days ahead | Low-traffic windows; emergency security changes may be applied immediately with notice after |
| Critical incident acknowledgement | 30 minutes during support hours | From the time a ticket is raised through the support channel |
| Data durability | Scheduled exports retained for 30 days | Per-instance exports to the firm’s storage |
Where we miss the monthly availability target in a given month, you may claim a service credit against the next invoice: 5% of that month’s fee for availability between 99.0% and 99.9%, and 15% below 99.0%. Credits are the sole remedy for a missed service level.
3. Support and response targets
Support is provided by the engineers who build the product, during the hours of your tier, through the support channel in your order form.
| Severity | Definition | First response | Update cadence |
|---|---|---|---|
| S1 — Critical | The firm cannot work: sign-in unavailable, data inaccessible, or a security incident | 30 minutes | Every hour until resolved |
| S2 — High | A core workflow is broken with no practical workaround (billing, portal, documents) | 4 business hours | Daily |
| S3 — Normal | A feature is impaired but work continues (reports, reminders, display issues) | 1 business day | As agreed |
| S4 — Request | Configuration, how-to questions and change requests | 2 business days | As agreed |
Support hours are 08:00–18:00 on business days in your firm’s time zone for Professional, and extended hours by agreement for Enterprise. S1 incidents outside those hours are handled on a best-efforts basis unless an extended support schedule is purchased.
4. Backup, restore and continuity
- The firm’s database is exported on a schedule and retained as described above, in storage that the firm controls or that is dedicated to the firm.
- Restore point objective: 24 hours. Restore time objective: 4 hours for a full firm restore, measured from a confirmed request during support hours.
- Restores are rehearsed on our own dogfood instance; the drill record is available on request.
- Files stored by the firm are replicated so that a single-object failure does not require a restore.
- Where the firm operates a bring-your-own-account deployment, backup configuration remains ours to operate but the storage lifecycle rules are visible in the firm’s own account.
5. Responsibility matrix
| Area | OpenLPM | Your firm |
|---|---|---|
| Hosting, patching, platform currency | ✓ | — |
| Software updates and rollback | ✓ | — |
| Monitoring, backup schedule, restore drills | ✓ | — |
| User accounts, roles and permissions | — | ✓ |
| Procedures, templates and firm configuration | — | ✓ |
| Data quality, client records, fee arrangements | — | ✓ |
| Professional and regulatory compliance | — | ✓ |
| Multi-factor authentication and staff device security | Shared | ✓ |
| Informing us of suspected compromise | — | ✓ (promptly) |
6. Security operations
- Access to a firm’s instance by our staff is limited to those who need it, and is recorded.
- We monitor availability and error conditions; we do not read client files as part of routine monitoring.
- Suspected vulnerabilities should be reported to security@openlpm.com; we acknowledge within one business day and keep you informed of remediation.
- Security-relevant changes are announced to administrators, including where a change requires action from the firm.
- Incidents affecting a firm’s data are notified without undue delay, with a written summary and remediation steps.
7. Data location and sub-processors
Managed deployments run on a defined infrastructure provider, with sub-processors used for email delivery, payments (only where the firm enables them) and error monitoring. A current list is provided with your order form; we give at least 30 days’ notice before adding a sub-processor that processes client data, and you may object.
Data is stored in the region selected at deployment. Transfers outside that region, if any, rely on appropriate safeguards described in the privacy notice.
8. Fair use and overage
Each tier includes storage, request and seat bands appropriate to a practice of that size. Where usage materially exceeds the band for two consecutive months, we will show you the usage and agree either an upgrade or an overage rate — never a silent charge.
9. Data return and exit assistance
- On request, and in any event within 30 days of termination, we provide a complete export of the firm’s data in open formats, plus the keys needed to operate the deployment.
- The deployment is retained during a handover window (30 days by default) so you can verify what you received.
- We assist with migration to a self-hosted deployment of the same software at no additional charge for the standard path.
- Deletion is confirmed in writing on request.
10. Credits, remedies and changes
Service credits are the sole financial remedy for missed service levels. Nothing in this schedule limits liability that cannot lawfully be limited under the Terms of Service.
We may change this schedule with 60 days’ notice where a change is needed for security, legal or platform reasons; changes that reduce a commitment are notified to administrators.