Skip to content

Support and Maintenance Description

AIMS-in-a-Box

  • Effective date: 9 September 2026
  • Last reviewed: 9 September 2026
  • Version: 1.0
  • Support channel: support@itsm-ltd.com

1. Overview

This document describes the support and maintenance ITSM Ltd provides for AIMS-in-a-Box (the “App”). It forms part of the End User Terms.

ChannelEmail only — support@itsm-ltd.com
Escalationsteven@itsm-ltd.com (see section 8)
Hours09:00–17:00 UK time (GMT/BST), Monday to Friday
Non-working daysWeekends and England & Wales public and bank holidays
LanguageEnglish. The App’s interface is also English only
EligibilityCustomers holding a current paid or trial licence
Commitment typeFirst-response targets — not resolution times

We are a small, focused team. We would rather commit to targets we consistently meet than publish an SLA we cannot honour. Everything below is written on that basis.

2. Who can raise a request

Support is available to:

  • Atlassian site administrators and named technical contacts of organisations holding a current paid licence for the App; and
  • users of an active evaluation or trial licence, on a reasonable-endeavours basis with no response target.

We may ask you to confirm your Support Entitlement Number (SEN) or the Atlassian site URL before we can act on a request.

3. How to raise a request

Email support@itsm-ltd.com.

Why the detail below matters. The App gives us no window into your site. There is no support console, no administrative back door and no way for us to view or reproduce your data — by design, and as described in section 6 of the Cloud Security Statement. Everything we diagnose, we diagnose from what you can see on your own screen and tell us. A well-described report is therefore the difference between a same-day answer and a week of exchanges.

Please include:

  1. The App name and version, and your Atlassian site URL or SEN.
  2. The affected page — the AI Management System workspace, the project settings page, the Jira administration page or the audit pack — and, if relevant, the project.
  3. What you expected to happen and what actually happened.
  4. Steps to reproduce.
  5. The date, time (with timezone) and approximate frequency of the issue.
  6. Screenshots or error messages, with any sensitive content redacted.
  7. Your assessment of business impact and the number of users affected.

Two places in the App answer “what changed and who changed it” without our involvement: the Activity view in the workspace, and the activity list on the administration page. Checking those first often resolves the question.

Please do not send credentials, API tokens or personal data that is not necessary to diagnose the issue. Anything you do send is handled in accordance with our Privacy Policy at https://aims.itsm-ltd.com/legal/privacy-policy.

4. Support hours and how targets are measured

4.1 Support hours are 09:00 to 17:00 UK time, Monday to Friday, excluding public and bank holidays in England and Wales.

4.2 Response targets are measured only during support hours. A request received at 16:45 on a Friday begins accruing time at 09:00 on the next business day. A request received at 09:15 on a Tuesday begins accruing immediately.

4.3 We do not provide 24/7, out-of-hours, weekend or telephone support.

4.4 Planned absences of more than 3 consecutive business days will be published on the App’s Marketplace support page and in the support inbox auto-reply, together with alternative arrangements.

5. Priority definitions and first-response targets

We set the initial priority from your description of impact and may adjust it after triage, telling you if we do.

PriorityDefinitionFirst-response target
P1 — CriticalThe App is unusable in production, or a defect in the App is causing data loss or corruption, or a confirmed security vulnerability is being exploited. No workaround exists.Within 4 support hours, and in any event within 1 business day
P2 — HighA major function of the App does not work, significantly impairing business operations for many users. A workaround may exist but is impractical.Within 1 business day
P3 — MediumA function does not work as documented, with limited business impact or an acceptable workaround. Includes configuration questions and minor defects.Within 3 business days
P4 — LowCosmetic issues, documentation queries, general how-to questions and enhancement requests.Within 5 business days

5.1 These are first-response targets: the time within which a person will read your request, assess it and reply substantively. They are not resolution times. Resolution depends on the nature of the defect and, where the cause lies in the Atlassian platform, on Atlassian.

5.2 For issues we accept as defects, we will confirm the priority, give an assessment of the cause and, where we can, an indicative timescale for a fix. We will update you at least weekly while a P1 or P2 defect remains open.

5.3 Where the root cause turns out to be an Atlassian platform fault, we will raise a ticket with Atlassian, give you the reference, and keep you updated — but the resolution timescale becomes Atlassian’s.

5.4 Security vulnerability remediation follows the timeframes in our Cloud Security Statement at https://aims.itsm-ltd.com/legal/cloud-security-statement and is tracked separately from this priority scheme.

6. What is in scope

  • Diagnosing and correcting defects in the App.
  • Answering questions about the App’s documented functionality and configuration.
  • Guidance on installing, upgrading and uninstalling the App.
  • Guidance on the App’s access model — how grants work, who can issue them, and what each level permits.
  • Advice on the App’s permissions, scopes and data handling.
  • Guidance on generating and saving the App’s documents, and on what you can export before uninstalling.
  • Assisting your security or procurement teams with questionnaires about the App.
  • Investigating and remediating security vulnerabilities in the App.
  • Reviewing enhancement requests and feeding them into our product planning.

7. What is out of scope

The following are outside this description. We will normally point you in the right direction, but we cannot commit time or targets to them.

7.1 Compliance advice

This is the most important boundary in this document, because of what the App is for. Support covers how the App works. It does not cover what you should do about ISO/IEC 42001 or the EU AI Act. Specifically, outside scope:

  • Interpreting ISO/IEC 42001 or Regulation (EU) 2024/1689, or advising how either applies to your organisation.
  • Advising whether a particular AI system is prohibited, high-risk, limited-risk or minimal-risk, or whether you are a provider or a deployer of it. The App applies published rules to the answers you give; the determination is yours (clause 9.4 of the End User Terms).
  • Reviewing, approving, correcting or commenting on the content of your generated documents, your control notes, your evidence or your readiness score.
  • Advising on whether you are ready for a certification audit, or on what an auditor or supervisory authority will accept.
  • Acting as, or standing in for, your legal adviser, auditor, certification body or consultant.

We are not an accredited certification body and we do not give legal advice — see section 9 of the End User Terms. Where you need that help, take it from a qualified adviser or an accredited body. We are happy to explain what the App records and how, which is often what an adviser actually needs from us.

7.2 Everything else outside scope

  • Faults in Atlassian products or the Atlassian Cloud, and Atlassian platform outages, quotas and rate limits. Raise these with Atlassian Support.
  • Faults in third-party apps, integrations or customisations, including interactions between the App and another Marketplace app.
  • Bespoke development, custom features, private branches or professional services. These may be available separately — contact support@itsm-ltd.com.
  • Training, consultancy, data migration and general Atlassian administration.
  • Support for versions of the App that are no longer supported (section 9).
  • Requests from customers without a current licence.
  • Recovery of data deleted from your Atlassian site or lost through uninstallation (see section 10).
  • Support in languages other than English.

8. Escalation

8.1 If you are not satisfied with progress, reply to the existing email thread with ESCALATION in the subject line, stating why. Escalations are reviewed by Steven Godson, Director (steven@itsm-ltd.com), and acknowledged within 1 business day.

8.2 If the matter remains unresolved, contact steven@itsm-ltd.com, which reaches Steven Godson, Director, directly.

8.3 Atlassian may also direct end-user enquiries to us. We maintain a current support email address in the Atlassian Marketplace vendor record for this purpose.

9. Maintenance, versioning and updates

9.1 How updates reach you. The App is a Forge app. Minor and patch releases are deployed by us and propagate automatically to every installation, without action by your administrators. You are therefore always running the current minor version of your major version. Major version upgrades, and any upgrade that adds a new permission scope, require explicit approval by your Atlassian site administrator.

9.2 Release cadence. We aim to publish maintenance releases monthly or as required. Security fixes are released as soon as they are ready, without waiting for a scheduled release.

9.3 Release notes. Release notes are published at https://aims.itsm-ltd.com/releases and summarised on the App’s Marketplace listing.

9.4 Supported versions. We support the current major version and the immediately preceding major version. Because minor updates are automatic, in practice all customers on a supported major version are current.

9.5 Continued maintenance. We commit to keeping the App actively maintained, including publishing at least one version update within every 18-month period, consistent with Atlassian’s requirements for maintained Marketplace apps.

9.6 Breaking changes. We will give at least 60 days’ notice before releasing a change that removes documented functionality or requires configuration work by you.

9.7 Changes to governance content. The App’s ISO/IEC 42001 control catalogue, its EU AI Act classification rules, its readiness questions and the contents of its generated documents may change as the standards, the law and its interpretation develop. Where such a change alters a result you have already recorded — for example by moving a control or changing how a system classifies — we will describe it in the release notes. Generated documents are immutable snapshots and are not retrospectively altered: a document generated last year remains the document as it stood, not this year’s rules applied to old data.

9.8 End of life. If we discontinue the App, we will give at least 90 days’ written notice to the technical contact on your licence and will support a pro-rata refund request to Atlassian for any unused portion of a paid Subscription Term.

9.9 Platform-driven change. Atlassian may change, deprecate or withdraw Forge capabilities. Where this materially affects the App we will notify you as early as we reasonably can, but we cannot control Atlassian’s platform roadmap or timescales.

10. Availability, backup and data recovery

10.1 No availability SLA. The App runs entirely on the Atlassian Forge platform. Its availability is a function of the Atlassian Cloud, which we neither operate nor control. We do not offer an uptime commitment for the App. Atlassian’s own service commitments, where they apply to your subscription, are made by Atlassian.

10.2 Backups. Atlassian Cloud backs up persistent storage, including Forge app storage, for platform disaster recovery. We hold no separate backup of your data.

10.3 Recovery, and what you can export. We cannot restore individual records, undo configuration changes, or recover data deleted from your Atlassian site or lost when the App is uninstalled.

If you need a copy of your data, take it before you make a destructive change or uninstall. We would rather tell you plainly what is possible than point you at a guide:

  • Generate the documents you need in the workspace — the AIMS policy, Statement of Applicability, risk register, AI system register, per-system impact assessments and roles and responsibilities document.
  • Open the audit pack, choose the version, and use Print or save as PDF. Your browser produces the file. That is the whole of the export mechanism.
  • There is no CSV export, no JSON export and no bulk download.
  • The audit trail cannot be exported. It is viewable in the App as a capped list of recent entries, and no generated document reproduces it. If you need a record of it, capture it from the screen before uninstalling.
  • Readiness assessment history and individual evidence records leave the App only insofar as they appear within a generated document.

We know this is narrower than customers expect of a governance tool, and we would rather you discover it here than the week you decide to migrate. Enhancement requests on this point are welcome and are tracked.

11. Your responsibilities

To let us support you effectively, please:

  • keep a nominated technical contact and a current email address on your Atlassian licence;
  • provide the diagnostic information in section 3 and respond to reasonable requests for further detail;
  • test significant changes in a sandbox or non-production Atlassian site before applying them in production;
  • keep your Atlassian products and other Marketplace apps within their supported versions;
  • review who holds Jira project administration on your site, since that determines who can grant access to the App; and
  • ensure the people contacting us have the necessary administrative access to act on our advice.

We may close a request if we have asked for information and received no response within 10 business days, having sent at least one reminder. You can reopen it at any time by replying.

12. Changes to this description

We may update this description. The current version is always published at https://aims.itsm-ltd.com/legal/support-and-maintenance. Where a change materially reduces the support you receive, we will give at least 30 days’ notice and the change will not reduce our obligations during your then-current Subscription Term.


Published in accordance with the Atlassian Marketplace Partner Agreement. Read alongside the Privacy Policy, End User Terms and Cloud Security Statement for AIMS-in-a-Box.

This document is one of five. The rest are on the legal index. Questions go to support@itsm-ltd.com.