Skip to content

docs(services): rewrite Security Response Team page from the Revenue … - #2388

Open
marcus-souza-azion wants to merge 2 commits into
mainfrom
feat/SRT-enhancement
Open

marcus-souza-azion wants to merge 2 commits into
mainfrom
feat/SRT-enhancement

Conversation

@marcus-souza-azion

@marcus-souza-azion marcus-souza-azion commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What & why

Related issue: MM-16038
Pages affected: /documentation/services/security-response-team/ · /documentacao/servicos/security-response-team/

What the page now carries:

  • Scope: the eight activities the SRT covers, each with what it means for the customer: incident response, security operations, WAF tuning, DDoS mitigation, bot protection, threat analysis, emergency change management, and critical production support.
  • Request flow: every engagement starts with a Support ticket; Support owns the ticket and the customer contact end to end, runs a pre-escalation revieupdates the ticket at least once per hour once escalated.
  • Request contents: what Support needs to reproduce and escalate a case(domain and route under attack, source IPs, monitoring data, outage status,evidence, summary).
  • Service level: P3 (Impactful Risk), 2-hour SLA, 24x7.
  • Contract and hours: contracted as a bundle with the Mission Critical support plan and DDoS Protection Unlimited; monthly hours package, unused hours do not roll over; billable-exception path for non-contracted customers.
  • Responsibilities: the customer stays responsible for its security and approves changes; no absolute guarantee; Support is the point of contact.

Follow-ups this PR does not touch:

  • DDoS Protection and DDoS mitigation pages (EN and PT) still describe the SRT as DDoS-only and as an add-on for Enterprise or Mission Critical in a :::tip.
  • Managed Configurations (EN and PT) still says the SRT mitigates "workload failures"; the PT line has a mixed-language typo.

Type of change

  • 🆕 New content (feat)
  • 🩹 Fix (fix) — typo, broken link, wrong information
  • ♻️ Content update (docs) — rewrite, expansion, upkeep
  • 🌐 Translation sync (i18n)
  • 🏗️ Platform / structure (refactor / chore) — reviewed by UXE, no content mixed in

Author checklist

  • PR title follows type(scope): summary (see GOVERNANCE.md §4)
  • Frontmatter complete: title, description, meta_tags, namespace, permalink, last_reviewed — the five fields are complete on both pages; last_reviewed is on zero pages corpus-wide and is not added here
  • No legacy "edge-" product names in the copy
  • How-to/tutorial content includes at least one runnable, copy-paste-tested code block — not applicable: this is an Overview of a service with no code artifact
  • Screenshots (if any) have alt text and follow image standards — not applicable: no images
  • Internal links are relative and resolve locally — root-relative with language prefix, all 26 resolve in dist
  • If any permalink changed or page moved: redirect added in this PR — no permalink changed
  • i18n: pt-br updated in this PR or follow-up i18n issue created:
  • I ran pnpm build:local (build + frontmatter check) without errors


Every engagement of the SRT starts with a Support ticket. [Technical Support](/en/documentation/services/support/) handles the ticket and every contact with you from start to finish, and the SRT performs the security work behind it. In an under-attack case, all communication with you happens through the ticket.

Support escalates a case to the SRT when the case needs deeper analysis, or when containing the attack goes beyond Support's break-and-fix scope. Typical escalations are attack or fraud response and solutions that require [Azion Marketplace](/en/documentation/products/marketplace/). The escalation is billable and requires the consent of your Customer Success Manager (CSM) or Account Executive (AE).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Contradicts steps 3 and 4. This says every escalation requires CSM/AE consent, but step 3 says Support engages the SRT directly when it's contracted, and step 4 says the SRT goes ahead when the CSM/AE can't be reached.

Scope it to the non-contracted case, e.g. "Without the SRT contracted, the escalation is billable and requires the consent of your CSM or AE."

Conflicting lines:

2. Support reproduces the case, collects the evidence, and runs the pre-escalation review with you.
3. Support confirms whether you have the SRT contracted. With the SRT contracted, Support opens the case with the SRT and engages it directly.
4. Without the SRT contracted, the SRT aligns the next steps with your CSM. When the SRT cannot reach your CSM or AE, for example outside business hours, it proceeds with the service. It informs you that the case is handled as an exception and aligns it with your CSM or AE afterward.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Playbook contracticts itself. We will have to check with the team if we must follow the playbook here or fix the contradiction.

1. You open a Support ticket that describes the attack or the security event.
2. Support reproduces the case, collects the evidence, and runs the pre-escalation review with you.
3. Support confirms whether you have the SRT contracted. With the SRT contracted, Support opens the case with the SRT and engages it directly.
4. Without the SRT contracted, the SRT aligns the next steps with your CSM. When the SRT cannot reach your CSM or AE, for example outside business hours, it proceeds with the service. It informs you that the case is handled as an exception and aligns it with your CSM or AE afterward.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Commercial commitment that needs Revenue/Legal sign-off. This publishes that Azion runs billable work without customer or CSM consent and aligns "afterward". Get explicit approval from the owner of the source document before merge.

Also, "It informs you" has the SRT contacting the customer, which contradicts L19 ("Support handles the ticket and every contact with you"). Change it to Support.

Conflicting line:

Every engagement of the SRT starts with a Support ticket. [Technical Support](/en/documentation/services/support/) handles the ticket and every contact with you from start to finish, and the SRT performs the security work behind it. In an under-attack case, all communication with you happens through the ticket.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We will need to verify the first one with the team.

The second line: Agreed, the sentence read as universal while steps 3 and 4 scope it. Fixed: "The escalation is billable. Without the SRT contracted, it also requires the consent of your Customer Success Manager (CSM) or Account Executive (AE)." This follows the source document's own escalation steps: a contracted customer is engaged directly, and the CSM alignment applies when the SRT is not contracted.


## Contract and hours

You contract the SRT as a bundle with the **Mission Critical** support plan and **DDoS Protection Unlimited**. The SRT is a monthly package of contracted hours. The hours are valid during the monthly period, up to the monthly limit in your contract. Unused hours do not roll over to the next month. Azion bills the SRT by the number of packages you contract. The number of hours per package is on the [Pricing](/en/documentation/products/pricing/#professional-services) page.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"DDoS Protection Unlimited" doesn't exist anywhere else in the docs, and the bundle claim conflicts with pricing.

  • DDoS Protection is unmetered and on in every account:
    At Azion, DDoS Protection is **unmetered** and is automatically enabled in all accounts. It offers protection against DoS and DDoS attacks with unmetered bandwidth. This means that, no matter how much DDoS attack traffic is directed to your applications or the Azion infrastructure, the Azion dedicated network will guarantee that all services are constant and not affected by the attack. As it's unmetered, mitigation using this protection won't appear on *billing*. For more information regarding traffic accounting, see the [pricing](/en/documentation/products/pricing/) page.
  • EN pricing lists the SRT as its own monthly line item:
    | Security Response Team| Monthly price |
    | :--- | :--- |
    | Up to 20 hours per month with the Security Response Team | $5,000 |
  • PT pricing labels the SRT "Add-on pago":
    | **Security Response Team**<br/>Equipe de especialistas em segurança para detectar, mitigar e responder prontamente a ameaças à segurança | --- | --- | Add-on pago | Add-on pago |

Either name the real SKU and update pricing in this PR, or drop the bundle claim.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the bundle sentence; the paragraph now opens "The SRT is a paid add-on, sold as a monthly package of contracted hours." and sends the reader to Sales or the CSM. The playbook checklist carries the legacy name and has been flagged for correction.

marcus-souza-azion pushed a commit that referenced this pull request Sep 23, 2026
…page

Apply the PR #2388 review in both languages:

- Scope the CSM/AE consent requirement to the non-contracted case, so
  it agrees with the escalation steps.
- Name the WAF mode with the docs term (Learning mode) instead of
  Counting Mode.
- Make Support the party that informs the customer in the exception
  path, consistent with the Support-only contact rule.
- Drop the internal "P3 (Impactful Risk)" priority label; keep the
  2-hour SLA and 24x7 work time.
- Remove the Mission Critical + DDoS Protection Unlimited bundle claim;
  the SRT is a paid add-on sold as a monthly package of hours.
- Rename the closing section to "Know more" / "Saiba mais".
…Process Playbook

Rebuild the SRT page (EN and PT) as an Overview so it no longer describes
the SRT as a DDoS mitigator only. The scope now carries the eight Playbook
activities: incident response, security operations, WAF tuning, DDoS
mitigation, bot protection, threat analysis, emergency change management,
and critical production support.

Adds the ticket-first request flow, the pre-escalation review, what to
include in the request, the service level, the contracted bundle and
monthly hours package, and the responsibilities from the Terms of Service.
Permalinks, namespace, and sidebar entries are unchanged.
…page

Apply the PR #2388 review in both languages:

- Scope the CSM/AE consent requirement to the non-contracted case, so
  it agrees with the escalation steps.
- Name the WAF mode with the docs term (Learning mode) instead of
  Counting Mode.
- Make Support the party that informs the customer in the exception
  path, consistent with the Support-only contact rule.
- Drop the internal "P3 (Impactful Risk)" priority label; keep the
  2-hour SLA and 24x7 work time.
- Remove the Mission Critical + DDoS Protection Unlimited bundle claim;
  the SRT is a paid add-on sold as a monthly package of hours.
- Rename the closing section to "Know more" / "Saiba mais".
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants