diff --git a/SUPPORT-SPONSORSHIP.md b/SUPPORT-SPONSORSHIP.md new file mode 100644 index 000000000..c3a452373 --- /dev/null +++ b/SUPPORT-SPONSORSHIP.md @@ -0,0 +1,23 @@ +# Echo Support Sponsorship Terms + +These terms apply to the Support tier on [GitHub Sponsors](https://github.com/sponsors/labstack), provided by LabStack LLC. + +## What you get + +- Everything in the Business tier. +- We aim to reply to your issues and questions within 2 business days. +- A named contact for security questions, and a heads-up on scheduled security release dates. +- A written summary of Echo's published support periods for the versions you use. +- Help answering SBOM and vulnerability questions for your compliance reviews. + +## Terms + +1. **Best effort.** Support is provided on a best-effort basis. Response times are goals, not guarantees. +2. **Security notice.** Advance notice covers only the planned release date and the affected version lines. Vulnerability details and fixes are published publicly, for everyone, at release time, following coordinated disclosure. See [SECURITY.md](./SECURITY.md). +3. **Support statements.** Support-period summaries restate Echo's public policy in [ROADMAP.md](./ROADMAP.md) and [SECURITY.md](./SECURITY.md), which may change. They are not a warranty. +4. **No warranty.** Echo is provided under the [MIT License](./LICENSE), "as is". Sponsorship does not change that. +5. **Liability.** LabStack LLC's total liability is limited to the sponsorship fees paid in the previous 3 months. +6. **Billing.** Billed through GitHub Sponsors under GitHub's terms, or invoiced by LabStack LLC. You can cancel anytime; past months are not refunded. +7. **Changes.** These terms may be updated. The current version is always in this file. + +Questions: [v@labstack.com](mailto:v@labstack.com)