WebService Service Description (Platform)
Service Level: L2 — Semi-Managed Cloud Service
This Service Description defines the functional and technical scope, support processes, and service level agreements (SLAs) for the cloud-based vHaaS WebService (Platform).
Pilot Phase — No Binding SLA
This service is currently in Pilot Phase (Closed Beta). No legally binding availability levels are guaranteed during this period. Vector makes all commercially reasonable efforts to meet the target values stated below and to proactively address any service degradation.
1. Subject and Scope
1.1 Scope of Agreement
The contractor provides the client with the vHaaS Cloud Platform Service. This service serves to orchestrate distributed physical devices and virtual assets, enabling global, centralized remote collaboration and seamless CI/CD integrations.
1.2 Service Boundary
This document covers the WebService (Platform) layer only. The contractor operates the central cloud platform (Application Service (AS)). Under this model:
- The Client is fully responsible for operating, maintaining, and housing the local hardware setups (Execution Environments and Assemblies) within their own or third-party managed facilities.
- The Contractor provides the central control plane, APIs, client-side software, and secure remote tunneling infrastructure.
For full-managed physical hosting of hardware, refer to the Hosting (Infrastructure) Service Description.
1.3 Usage Rights and Restrictions
- Internal Use Only: The service is intended solely for the client's internal operational needs and collaboration within designated Tenants (including authorized partner companies).
- Reselling Prohibition: The client is strictly prohibited from leasing, renting, reselling, or distributing the service or any of its components as a standalone commercial product to third parties.
- Geographic Restrictions: Access from embargoed or sanctioned countries (e.g., China, North Korea) is technically and contractually restricted to comply with export control regulations.
2. Definitions
| Term | Definition |
|---|---|
| Application Service (AS) | The central cloud-based SaaS platform serving as the primary interface for users and CI/CD pipelines. Handles asset scheduling, calendar bookings, device control, monitoring, REST APIs, and identity/access management (IAM). |
| Execution Environment (EE) | A dedicated physical or virtual computing unit (e.g., NUC, PC, VM, Raspberry Pi) that acts as the remote development workstation. |
| vHaaS Agent | A lightweight software component installed on the EE that acts as a secure, outbound-only bridge between the central cloud AS and the local workspace hardware. |
| Assembly | A logical grouping of interconnected hardware components (e.g., ECUs, bus interfaces, power supplies, measurement instruments) defined for a specific test scenario. |
| Workspace | A virtual entity defining an exclusive development session. Bundles one or more EEs and Assemblies, ensuring that only one user (or CI/CD runner) has access to the physical system at any given moment. |
| Hardware Automation Interface (HAI) | A REST API layer allowing programmatic, physical control (e.g., Power On/Off, Reset) and status monitoring of an Assembly via the Agent. |
| Assembly Profile | A digital representation ("Infrastructure as Code") of the physical hardware cabling, pins, and interfaces used by the AS for visual layout rendering and automated routines. |
| Request Profile | A configuration template used in CI/CD pipelines to dynamically locate, book, and spin up matching workspaces based on technical capability matching. |
3. Functional Scope
3.1 Application Service (Platform)
- Centralized Management Web UI: A web console to manage organizations, users, roles, groups, and catalog hardware resources.
- REST API: A fully featured, well-documented REST API for programmatic control over scheduling, session creation, and device automation.
3.2 Connectivity & Remote Access
- Browser-Based Remote Desktop: High-performance desktop streaming directly within any modern web browser — no local VPN client required.
- Secure SSH Tunneling: End-to-end encrypted terminal access at console level.
3.3 Automation & CI/CD Integration
- CI/CD Connectors: Native integration plugins and templates for GitLab CI, GitHub Actions, and Jenkins.
- Dynamic Resource Scheduling: Conflict-free booking engine preventing simultaneous access to physical assets.
3.4 Client Software
- vHaaS Agent: Lightweight, zero-configuration executable for installation on client-managed EEs.
- vHaaS CLI: Python-based, open-source command line tool for scripting and local workflow automation.
4. Service Level Agreement (SLA)
Availability commitments apply strictly to the central Application Service (AS) cloud control plane. Local hardware availability (managed by the client) is excluded.
4.1 SLA Metrics
| Metric | Target Standard SLA | Pilot Phase SLA |
|---|---|---|
| Platform Availability | 99.5% (monthly average) | Best Effort — no legal guarantee |
| Support Window | Mon – Fri, 08:00 – 17:00 CET | Mon – Fri, 08:00 – 17:00 CET |
| Incident Response Time (Critical) | ≤ 4 hours | Best Effort |
4.2 Availability Calculation
$$\text{Availability} = \frac{\text{Total Time} - \text{Planned Maintenance} - \text{Downtime}}{\text{Total Time} - \text{Planned Maintenance}} \times 100\%$$
Planned maintenance windows announced in advance are excluded from the availability calculation.
5. Updates and Maintenance
The Application Service, vHaaS Agent, and HAI software follow a structured release lifecycle based on semantic versioning (Major.Minor.Patch).
Pilot Phase
During the pilot phase, Vector reserves the right to deploy updates outside regular cycles, including breaking changes, after prior announcement.
| Update Type | Frequency | Notice Period | Description |
|---|---|---|---|
| Major Release | Every 6 months | 2 months | New major features; may include documented breaking changes. |
| Minor Release | Monthly | 2 weeks | Non-breaking feature additions and performance improvements. |
| Patch / Hotfix | As needed | 3 days (where possible) | Bug fixes and stabilization patches. |
| Security Update | As needed | Prior to rollout | Critical CVE remediation; applied within 3 days of disclosure. |
6. Support Services
6.1 Support Tiers
[Client Users / Pipelines]
│
▼
[1st Level Support — Client-Internal] ──► Local hardware & configuration issues
│
▼ Escalation of platform bugs
[2nd Level Support — vHaaS Platform Team] ──► REST API, Agent & AS bugs
│
▼ Development escalation
[3rd Level Support — Engineering] ──► Bugfixes & core platform changes
6.2 Incident Severity Classification
Incidents are classified into four priority levels. Response time begins when the ticket is opened within the support window. Resolution time is a target, not a contractually binding commitment during the Pilot Phase.
| Priority | Definition | Initial Response (Target) | Resolution (Target) |
|---|---|---|---|
| P1 — Critical | Complete platform outage or full loss of access for all users; no workaround available. | 1 hour | 4 hours |
| P2 — High | Major feature unavailable or significantly degraded for a subset of users; limited workaround available. | 2 hours | 8 hours |
| P3 — Medium | Non-critical feature impaired; workaround available; limited operational impact. | 4 hours | 3 business days |
| P4 — Low | General queries, feature requests, minor UI issues, documentation questions. | 1 business day | Best effort |
Support window: Mon – Fri, 08:00 – 17:00 CET. Contact via ticket system; phone escalation for P1/P2.
6.3 Problem Management
For P1 and P2 incidents, the vHaaS platform team conducts a root cause analysis. The client receives a written Post-Incident Report (PIR) within 5 business days of incident resolution, covering the timeline, root cause, impact assessment, and implemented or planned corrective actions.
7. Licensing & Commercial Model
- User-Based Licensing (Seat Model): Licensing is per active user per month. A user account is considered active if at least one login or API interaction occurred within the billing month.
- Included: Full access to the Application Service, all platform features, and usage rights for the vHaaS Agent. The CLI tools are open-source and not part of the license.
- Billing: Monthly or annually in advance. Upscaling during the term is possible at any time.
- Modular Add-ons: Additional tenants, extended audit log retention, or advanced automation capacity can be added on request.
8. Third-Party Providers & Licenses
The following strategic third-party providers are used to deliver this service:
| Provider / Technology | Role | Data Protection Relevance |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of the cloud infrastructure (Application Service (AS)) | Infrastructure sub-processor |
| Cloudflare | Network security, DDoS protection, Zero Trust tunneling for secure remote access | Security & transport layer |
| Microsoft Entra ID / Okta (Auth0) | Identity Provider (IdP) for authentication and authorization (SSO, MFA) | Identity management |
| Apache Guacamole | Foundation for browser-based remote desktop streaming | Open-source component |
| Material UI (MUI) | Frontend component library | UI framework |
Security & Data Protection
For the full security architecture, GDPR/DSGVO compliance details, Technical and Organizational Measures (TOMs), and certification status, refer to the Security & Compliance section.
9. Data Management & Privacy
9.1 Backup & Restore
Platform configuration data (tenant settings, user accounts, hardware catalog, workspace definitions) is backed up automatically.
| Parameter | Value |
|---|---|
| Backup Frequency | Daily (incremental); weekly (full) |
| Retention Period | 30 days |
| Recovery Point Objective (RPO) | ≤ 24 hours |
| Recovery Time Objective (RTO) | ≤ 8 hours |
| Restore Testing | Quarterly restore tests are conducted to verify backup integrity |
Note
Customer-generated content (e.g., files on Execution Environments) is not within the scope of the platform backup. Clients are responsible for their own data on EEs.
9.2 Data Deletion & Offboarding
Upon contract termination, the contractor ensures orderly data deletion in accordance with GDPR:
- All personal data and customer configuration data stored in the Application Service is deleted within 30 days of contract end.
- The client receives a written deletion confirmation upon request.
- Prior to deletion, the client may export their configuration data via the REST API or request a structured data export from the support team.
9.3 Metadata Usage
Vector may process aggregated, anonymized usage metadata (e.g., feature usage patterns, session telemetry) to operate, maintain, and improve the vHaaS platform, as defined in the Pilot Agreement.
9.4 Sub-Processor Changes
The current list of sub-processors is maintained in §8 of this document. The contractor will notify clients of any additions or replacements to the sub-processor list with a minimum notice period of 30 days before the change takes effect, giving clients sufficient time to raise objections under GDPR Art. 28.
10. Security Operations
10.1 Penetration Testing
The Application Service undergoes regular security assessments conducted by an independent, accredited third-party provider.
| Parameter | Details |
|---|---|
| Frequency | At minimum annually; additionally after each Major Release |
| Scope | Web application layer (OWASP Top 10), REST API, authentication flows, network perimeter |
| Conducting Party | Accredited external security firm (third-party, independent of the development team) |
| Last Assessment | May 2026 — all findings remediated |
| Client Attestation | Upon request, clients receive an executive summary confirming the test was performed and critical findings were remediated. Full reports are not shared but can be referenced in audits under NDA. |
10.2 Vulnerability Management
Beyond scheduled patching (§5), the contractor operates a continuous vulnerability management process:
- Monitoring: Automated scanning of all platform components for known CVEs using industry-standard tooling.
- Classification: Vulnerabilities are triaged based on CVSS score. Scores ≥ 9.0 (Critical) are treated as P1 incidents; scores ≥ 7.0 (High) are remediated within 7 days.
- Disclosure: Clients are notified of critical vulnerabilities that could directly affect their data or access security, along with the remediation status.
10.3 Audit Log Retention
All security-relevant actions on the platform (logins, permission changes, workspace access, API calls) are logged and retained.
| Log Category | Retention Period |
|---|---|
| Authentication & Access Events | 12 months |
| Administrative Actions | 12 months |
| API Activity | 90 days |
Logs are available to clients for their own tenant scope via the platform UI or API. Forensic access to infrastructure-level logs can be provided upon request in the context of an active security incident.
10.4 Personnel Security
All Vector employees and contractors with access to production systems or customer data are subject to:
- A pre-employment background check in accordance with applicable local law.
- Mandatory confidentiality agreements (NDA) as part of their employment or contractor contract.
- Role-based access controls ensuring that access to customer data is limited to personnel with a justified operational need (principle of least privilege).
- Regular security awareness training.
10.5 Customer Audit Rights
Clients may request evidence of compliance with the security measures described in this document and the associated TOMs. Vector will respond to audit questionnaires and provide relevant attestations (e.g., pentest summary, third-party certifications). On-site audits by the client or a commissioned third party may be agreed upon separately.
11. Service Reporting
Clients receive a monthly service report covering the previous calendar month. The report is provided via the ticket system or a designated contact channel and includes:
- Availability: Measured uptime of the Application Service against the SLA target, excluding planned maintenance.
- Incident Summary: List of P1 and P2 incidents, including duration, impact, and resolution status.
- Maintenance Overview: Completed and planned maintenance windows.
- Patch & Release Status: Summary of updates deployed during the reporting period.
Pilot Phase
During the pilot phase, service reports are provided on a best-effort basis. The format and delivery cadence may evolve as the service matures.