1. Scope
Managed services cover only systems, components and tasks identified in the plan or statement of work. Work outside scope may require a change request or additional fee.
2. Administrative access
Customers authorize AlpineLayer to use privileged access reasonably necessary to perform managed work. AlpineLayer should use secure credential handling, MFA and approved access paths.
3. Changes
Routine work may occur during agreed windows. Higher-risk changes may require approval, a backup and rollback plan. Emergency security changes may be implemented quickly where needed to contain material risk.
4. Customer responsibilities
Customers remain responsible for business logic, code, data accuracy, licenses, business decisions and systems outside managed scope.
5. Monitoring
Where included, AlpineLayer monitors agreed infrastructure indicators. Monitoring cannot guarantee detection of every application or security issue.
6. Backup
Backup management is included only where stated; the Backup Policy also applies.
7. Emergency action
Emergency remediation may be performed to protect availability, security or data where delay would create material harm. Significant actions should be documented.
8. End of service
On termination, AlpineLayer will remove managed access and provide reasonable handover information within scope.