Aller au contenu principal
Version 0.2Brouillon

SLA and support

Overview

This page sets out LuxID's service-level commitments to Partners - 99.90% availability, maintenance windows, four-tier incident priority, support channels and DORA mapping - with binding terms in the executed LuxID Agreement SLA annex.

This page documents the service-level commitments LuxID makes to Partners, the support channels available, and how the SLA maps to regulated Partners' own compliance obligations (in particular DORA for financial services Partners).

The binding service-level terms are set out in the SLA annex of the executed LuxID Agreement. The figures here reflect the standard SLA; Partners with negotiated terms should refer to their executed agreement.

Two definitions used throughout this page:

  • Business Day: Monday to Friday excluding Luxembourg public, statutory and bank holidays.
  • Business Hours: 08:00 to 16:00 CET on Business Days, unless a specific service states otherwise.

Availability

Availability target

LuxID targets 99.90% availability for the authentication service (login.luxid.lu), measured per calendar quarter.

99.90% over a quarter allows up to roughly 130 minutes of unplanned downtime in any given quarter. Availability is the percentage of in-scope service time during which the authentication endpoint is reachable and returning successful authentication responses, excluding scheduled maintenance.

What is covered

The availability target covers:

  • The LuxID Universal Login hosted page (login.luxid.lu)
  • The OIDC token endpoint and userinfo endpoint
  • The SAML SSO endpoint
  • The account management interface (account.luxid.lu) for user-facing features

What is excluded

The following are not covered by the availability target:

  • Scheduled maintenance windows (see Maintenance Windows)
  • Incidents caused by Partner-side failures (expired certificates on Partner redirect URIs, incorrect configuration with LuxID)
  • Force majeure events
  • UAT environment (login-uat.luxid.lu) - the UAT environment carries no availability SLA; it is a best-efforts test environment
  • Third-party dependencies outside LuxID's control (for example, SMS delivery for OTP via mobile network operators)

Measuring and reporting

During an incident, LuxID notifies each Partner's registered technical contact by email. Keep that contact list current for proactive incident awareness.

Quarterly availability statistics are included in the Partner report (see Partner Reporting).


Maintenance windows

Planned maintenance

Planned maintenance that may affect service availability is announced at least 3 Business Days in advance, by email to the Partner's registered technical contact.

Planned maintenance is performed outside Business Hours (so outside 08:00-16:00 CET on Business Days). If a Partner objects to the proposed window within 2 Business Days of the notice, LuxID and the Partner agree a new date. If no objection is raised within that window, the maintenance proceeds as scheduled.

Maintenance during a planned window does not count against the availability target.

Emergency maintenance ("urgent security matter")

When an Urgent Security Matter (an event that could affect the security or stability of LuxID, for example a new critical vulnerability or active attack) requires immediate corrective work, POST may modify, restrict or suspend the service without prior notice. Partners are notified at the latest 24 hours after detection, with the relevant details and the measures taken.

This 24-hour clock is contractual to LuxID and is independent of the 72-hour GDPR Article 33 statutory clock that applies if the incident also qualifies as a personal data breach (see GDPR and Data Protection - Breach Notification).

Partner-initiated changes that may affect service

Two notification duties run the other way:

  • Configuration changes on the Partner side that could trigger alarms or briefly disrupt the integration must be flagged to POST at least 2 Business Days in advance so monitoring can be adjusted.
  • Marketing campaigns, application launches or feature releases that are likely to cause an unusual spike in authentication load must be flagged at least 2 Business Days in advance so POST can allocate capacity and distinguish the spike from anomalous traffic.

Both notifications go to the POST Customer Service Centre (see Support Channels).


Incident priority classification

LuxID classifies incidents on a four-tier priority scale. The clocks below are measured from the moment the incident is logged with the POST Customer Service Centre, not from when the incident began.

PriorityDescriptionResponseInterventionUpdate cycle
P1 - CriticalComplete failure of the service; the Partner application cannot use LuxID at all and there is no acceptable workaround.< 15 min1 hour2 hours
P2 - HighMajor degradation; important features unavailable with no workaround, or sporadic complete failure, or serious impact on Partner productivity.< 15 min2 hours3 hours
P3 - MediumModerate impact; important feature unavailable but a workaround exists, less significant feature unavailable, or limited operational impact.< 15 min4 hoursn/a
P4 - LowNo impact on the service or on the Partner's daily operations (cosmetic issue, documentation question, minor UX defect).best effortbest effortn/a

The targets are: Response = first acknowledgement; Intervention = work has actively started; Update cycle = the cadence at which Partners are kept informed while the incident is open. There is no contractual resolution time - incidents are worked through with best efforts after intervention begins.

Priority determination

Initial priority is assigned by the Partner when raising the ticket, but POST may reclassify based on the impact assessment. When in doubt, err towards higher priority - it is always possible to downgrade once the impact is clear.

P1 escalation

astuce

For P1 it is highly recommended to call the POST Customer Service Centre directly on 2424 3030 in addition to logging the ticket by email. Partners experiencing a confirmed P1 should not wait for the email response before escalating; use all channels simultaneously.


Support channels

Standard support - POST customer service centre

The POST Customer Service Centre is the first point of contact for all Partner incidents and service requests:

ChannelContactHours
Phone (P1 recommended)2424 3030Business Days during Business Hours
Email (all priorities)LuxIDBusiness Days during Business Hours

A self-service LuxID Console for status checks and configuration changes is on the LuxID roadmap; until it ships, the operational channels above apply.

Mailbox routing. servicedesk@post.lu is the Partner-facing support address. End-user support runs through support@luxid.lu, and commercial relationship questions (pricing, contract amendments, billing) go to hello@luxid.lu or the dedicated POST Luxembourg account manager. Routing an incident to the wrong mailbox delays response.

Account management

Partners with a dedicated POST Luxembourg account manager should use that contact for:

  • Commercial discussions (billing queries, contract amendments, pricing)
  • Roadmap and feature requests
  • Escalation of support issues that have not received a timely response
  • Partnership development discussions

If you do not know who your account manager is, write to LuxID.

Security incidents

Security incidents (suspected breaches, vulnerability reports, authentication anomalies that may indicate an attack) should be reported to LuxID with the subject line "SECURITY INCIDENT". This subject line triggers an expedited routing to the POST security team, separate from the standard support queue.

For responsible disclosure of security vulnerabilities, the same address applies. POST will acknowledge receipt within 1 Business Day.


Support tiers

LuxID currently offers standard support to all Partners under the terms of the LuxID Agreement. Premium support arrangements (dedicated technical account management, enhanced SLA, priority escalation) may be available for large-scale or high-criticality integrations. Contact your POST Luxembourg account manager to discuss.


Partner reporting

LuxID provides Partners with a quarterly report covering:

  • Authentication volume (successful authentications, failed attempts, MFA step-ups)
  • Availability statistics for the preceding quarter (uptime percentage, incident count)
  • Incident summary (any P1 or P2 incidents: duration, cause, intervention timeline)
  • Deprecation notices and upcoming changes (where applicable)

The quarterly report is delivered to the Partner's registered technical contact.

Partners may request ad hoc reports (for example, for regulatory audit purposes) by contacting LuxID. Complex ad hoc reports may incur additional processing time.


DORA considerations for financial services Partners

Financial services Partners subject to Regulation (EU) 2022/2554 (opens in a new tab) (Digital Operational Resilience Act) must manage LuxID as an ICT third-party service provider (TPSP) dependency. This section summarises how LuxID maps to DORA requirements.

DORA article 28 - ICT third-party risk

DORA Article 28 requires financial entities to maintain a register of ICT third-party dependencies and to conduct due diligence on critical TPSPs. LuxID's position in the Partner's DORA register:

DORA elementLuxID position
Service descriptionAuthentication-as-a-service: identity verification and session management
Criticality assessmentPartners should assess based on the proportion of their users who rely exclusively on LuxID sign-in. If LuxID is the sole authentication method, LuxID is likely a critical TPSP.
Business continuity impactAssess maximum tolerable downtime (MTD) against LuxID's 99.9% availability target.
Concentration riskLuxID is the only LuxID; however, LuxID Pro allows corporate IdP federation, providing an alternative authentication path for enterprise users.

DORA contractual requirements (article 30)

DORA Article 30 mandates specific contractual provisions for agreements with ICT TPSPs. The LuxID Agreement is designed to cover these requirements, including:

  • Service description and measurable service levels (covered in the LuxID Agreement and this SLA)
  • Incident notification obligations (see Support Channels and GDPR and Data Protection - Breach Notification)
  • Audit rights (the LuxID Agreement grants the Partner reasonable audit and evidence rights)
  • Sub-contracting: POST Luxembourg may use subcontractors and remains fully liable for them under the LuxID Agreement; subcontracting documentation is available on request
  • Termination and exit provisions: covered in the LuxID Agreement

Partners conducting DORA due diligence on LuxID should contact LuxID with their specific documentation requirements. LuxID will provide a DORA evidence pack including:

  • Completed regulatory due diligence questionnaires
  • Summary of security controls (ISO 27001 status, pen test summary)
  • Business continuity and disaster recovery overview
  • Sub-processor list
  • Incident notification procedure

DORA incident reporting

DORA introduces specific incident reporting obligations for financial entities to their national competent authority (NCA) for major ICT incidents. If a LuxID incident causes or contributes to a major ICT incident for a financial Partner:

  • LuxID will notify the Partner as described in Support Channels and GDPR and Data Protection - Breach Notification
  • The Partner is responsible for its own DORA incident report to the CSSF (for Luxembourg-regulated entities) or other applicable NCA
  • LuxID will cooperate with the Partner's incident investigation and provide evidence on request

Business continuity and disaster recovery

LuxID is operated on redundant infrastructure within Luxembourg. The binding business-continuity and disaster-recovery commitments - including Recovery Time Objective (RTO), Recovery Point Objective (RPO), backup regime and geographic redundancy - are defined in the SLA annex of the executed LuxID Agreement, as the applicable values depend on the service scope.

Partners requiring detailed BCP/DR documentation for their own risk management or regulatory purposes (for example, a DORA operational-resilience assessment) should contact LuxID.


Mise à jour le 2026-07-02