support.sanctumsecops.com — access-gated

Service desk

Four ways in. One of them wakes somebody up.

The severity definitions, the intake paths and the response posture, stated before you need them rather than during. A response commitment exists where a retainer exists; where one does not, this page says so instead of implying otherwise.

Portal host support.sanctumsecops.com — hosted service desk, reached by name only, no Sanctum origin behind it.

Intake

Which path to use

Each path states what it is for and whether it carries an obligation. The last column is the one that matters at 3am.

Access-gated

Service desk portal

The ticketing portal at the support hostname. Every ticket carries a severity, a named owner and a state; the state is a fact about the ticket rather than a reassurance about it.

Use it for

Anything with a ticket number attached to it: defects, change requests, enrolment problems, profile questions.

Response obligation

S2 and below are worked against the queue. An S1 raised here is acknowledged, but the retainer contact path is the one that reaches somebody out of hours.

Retainer contact path

The named path agreed in a retainer agreement, covering the hours and the severity levels written into that agreement. Established at onboarding, before it is needed.

Use it for

S1 and imminent S2. Key compromise, mis-issuance, revocation failure, estate-wide issuance failure.

Response obligation

This is the only path that carries a contractual response commitment, and the commitment lives in the agreement rather than on this page.

Knowledge base

The public self-service article index. Ungated, indexable, and exported as a plain-text corpus so a retrieval system can read it without scraping the portal.

Use it for

Enrolment procedures, validation methods, CSR requirements, revocation semantics, PQC profile questions.

Response obligation

None. It is documentation, and it says so.

Direct contact

Email and telephone to the company record. Reaches a person rather than a queue, which is an advantage until it is a single point of failure.

Use it for

Commercial questions, scoping, and anything that is not yet an engagement.

Response obligation

No response obligation. A production incident sent to a mailbox is a production incident nobody has been paged about.

Severity

Four levels, defined as conditions rather than adjectives

Severity is decided by what is true, not by how the ticket is worded. Every level below lists the conditions that qualify, so nobody has to argue about whether something is urgent.

Severity definitions and response posture
LevelQualifies whenResponse posturePath
S1 CriticalA production trust failure. Certificates cannot be issued or validated, a private key is suspected compromised, or a revocation cannot be published.Continuous work until contained, with the response commitment written into the retainer agreement rather than into a page that can be edited later.Retainer contact path, out of hours included. Escalates directly to the incident response engagement.
S2 HighDegraded trust operations. Issuance or lifecycle automation is impaired, or an expiry event is imminent and unmitigated.Worked in business hours with a named owner from acknowledgement, and escalated to S1 the moment an expiry or exposure becomes unavoidable.Service desk ticket, flagged at S2. Reviewed against the retainer response commitment.
S3 NormalA defect, question or change request with a workaround available and no dated consequence.Queued and worked in order, with the ticket carrying the owner and the current state rather than a status word.Service desk ticket. The knowledge base answers a material share of these without a ticket at all.
S4 InformationalAdvisory requests, documentation corrections and scheduled work with no operational consequence.Answered in order. Recurring S4 questions are converted into knowledge base articles rather than answered twice.Service desk ticket or email.

Severity is reassessed as facts change. An S2 with an expiry inside the renewal window becomes an S1 when the window closes, without waiting for anyone to ask.

S1 — Critical: what qualifies

  • Issuing CA unavailable and certificate renewals are failing across the estate
  • Suspected private key compromise on a signing or issuing key
  • Revocation distribution point or status responder unreachable
  • Mis-issuance discovered: a certificate exists that no profile permits

S2 — High: what qualifies

  • Renewal automation failing for a subset of hosts with expiry inside the window
  • Enrolment path rejecting valid requests for one tenant or one device class
  • Monitoring reporting policy drift that cannot be reconciled against issuance records
  • Composite profile failing validation on a production terminator

Boundaries

What the desk cannot do for you

Stated here because the alternative is a customer discovering it during an incident.

Limits of the desk

  • The desk does not hold your private keys and cannot recover one. A key that cannot be produced is a key that has to be rotated, and that is an S1.
  • The desk cannot revoke on your behalf without the authorisation the profile requires. Revocation is a POST that carries the authorisation and the reason, and a ticket is not either of those.
  • Response commitments exist only where a retainer exists. Without one, every path here is best effort and the site says so rather than implying otherwise.
  • The portal is operated on a hosted service desk platform. Anything you attach to a ticket lands there, so an artifact that cannot leave your environment should be described in the ticket and produced through the retainer path instead.

Direct

If you would rather reach a person

Telephone +1 (607) 378-8287Email [email protected]Desk support.sanctumsecops.com

Most S3 questions are already answered

The knowledge base covers enrolment, validation methods, CSR requirements and revocation semantics. Recurring questions become articles rather than being answered twice.