Web Maintenance Service Level Agreement (SLA)
Last updated September 15, 2026
This Service Level Agreement (SLA) applies to PixelMongers maintenance plans for WordPress-based websites, including Maintenance Essentials, Essentials Plus, and Business Premium.
By purchasing, paying for, or issuing a purchase order for a PixelMongers (PXM) maintenance plan, you (“Client”) acknowledge and accept the following terms and conditions:
Services Provided
PXM agrees to provide regular maintenance and support services for Client’s WordPress website(s) as detailed in the chosen maintenance plan (Maintenance Essentials, Essentials Plus, or Business Premium).
Services include:
- Regular WordPress core, plugin, and theme updates.
- Security monitoring and threat mitigation.
- Restoration from available backups.
- Troubleshooting and issue resolution within the defined service scope.
- Assistance with third-party integrations, including Microsoft Email API, Google Email API, Constant Contact, Emma, Salesforce, HubSpot, and similar platforms.
Included Support Hours and Additional Time
Maintenance Essentials includes 1.5 hours per quarter (up to 6 hours per plan year), and Essentials Plus includes 1 hour per month (up to 12 hours per plan year). Unused hours carry forward within the plan year and expire at renewal. Hours cannot be drawn in advance from future periods. When a single agreement or purchase order covers multiple websites, included hours may be pooled and applied across all sites it covers.
The plan fee covers the following without using included hours: scheduled WordPress core, plugin, and theme updates; automated security scans and monitoring; the periodic site review; and agency-managed plugin licenses.
All other work is logged against included hours in 30-minute increments. This includes content update requests, troubleshooting, security configuration and hardening, malware removal and incident response, backup restoration, and third-party integration support.
Once included hours are used, additional time may be billed at PXM’s current standard hourly rate. State of Oklahoma agencies are billed at the applicable rate in PXM’s SW0135 rate card for the current contract year, and billed time must be covered by the agency’s purchase order. PXM will notify the client before non-urgent work exceeds the remaining balance. Active security incidents may require immediate action to prevent data loss or further compromise; in those cases, PXM will begin work and notify the client as soon as practicable.
Client Responsibilities
The Client agrees to:
- Provide timely and accurate information required for performing maintenance.
- Ensure administrative access is available to PXM for website management.
- Provide server-level administrative access or ensure easy access to IT staff managing the hosting server for site backups, staging environments, and troubleshooting purposes.
- Keep PXM informed of any changes that could impact website functionality or security.
- Provide a written retention period for any website form that stores submissions.
Security Requirements
To comply with PXM’s cybersecurity policies and insurance requirements, all websites managed under a maintenance plan must:
- Have an approved security plugin installed and maintained (e.g., Wordfence, Kadence Security Pro, or equivalent).
- Enforce two-factor authentication (2FA) for all administrator-level user accounts.
These measures are mandatory to protect the integrity and security of your website and data.
Security Updates and Incident Response
Security releases for WordPress core, plugins, and themes are applied as part of the plan fee and do not use included support hours. On sites using automatic updates, releases are installed as they are published; on other sites, critical security releases are applied within 2-3 business days of release.
All hands-on security work uses included support hours, including initial setup of the required security plugin and 2FA, additional hardening or configuration, and investigation, cleanup, and recovery after a compromise. Time beyond the available balance may be billed at the applicable hourly rate. PXM does not bill for remediating a compromise caused by PXM failing to enable or maintain the site’s update process as described above.
Third-Party Software Risk
WordPress core, plugins, and themes are developed and distributed by third-party vendors. PXM cannot prevent vulnerabilities that have no available fix, or compromised updates published through a vendor’s official channels (supply-chain attacks). Automatic updates reduce exposure to known vulnerabilities, but may also install a compromised release before it is publicly identified. Plugins licensed through PXM’s agency accounts remain third-party software. PXM is not the vendor.
When PXM becomes aware of a compromised or unsafe plugin or theme, PXM will remove, disable, or replace it and notify the client. Investigation and cleanup follow the incident response terms above.
Compensation and Payment
Client agrees to compensate PXM under the terms of their selected maintenance plan. Pricing may vary based on project scope, renewal terms, or legacy status. All maintenance plans require a minimum 12-month commitment.
Clients may choose monthly or annual billing, with payment due either in advance or within 15 days of the start of each maintenance period, depending on the agreement. Accepted payment methods include credit card, check, bank transfer, or authorized purchase order.
Maintenance invoices will clearly specify coverage dates. PixelMongers reserves the right to adjust maintenance rates annually to reflect increased operational costs, cybersecurity requirements, and evolving state procurement expectations. Pricing adjustments, if applicable, will be noted on the client’s invoice for the upcoming billing period.
Support Response Times
PXM strives to respond to support tickets within 24 hours during the business week (Monday–Friday, 9:00 AM – 5:00 PM CST). Clients should submit support requests by emailing [email protected]. For urgent or complex issues, clients with direct contact details may escalate through Basecamp pings, Microsoft Teams chat, or via SMS if previously authorized.
In the event of critical security threats, service outages, or disaster recovery scenarios, PXM may extend availability beyond standard hours to ensure timely resolution and protection of client sites.
In situations requiring after-hours support that is not caused by PixelMongers-managed systems or covered under the standard maintenance plan, emergency assistance may be billed at a higher hourly rate. This rate is calculated at time-and-a-half. Clients will be informed of applicable fees prior to any work being performed, unless immediate intervention is necessary to prevent significant service disruption or data loss.
Exclusions and Additional Services
The following are not included in standard maintenance plans but may be available as additional services:
- New page layouts, landing pages, or custom designs.
- Full website redesigns or rebuilds.
- WCAG 2.1 AA or ADA compliance remediation.
- Custom development or advanced programming.
These are billed separately at PXM’s current standard hourly rate or under a separate proposal.
Refund Policy
Refunds are applicable only to prepaid maintenance plans and retainers under the following conditions:
- A prorated refund may be issued if no services have been rendered in the billing cycle.
- No refunds will be issued once updates, backups, or content changes have occurred.
- Requests must be made in writing within 30 days of payment.
- One-time or project-based services are non-refundable once begun.
Data Handling and Compliance
PixelMongers does not collect, store, or manage sensitive or regulated data as part of its maintenance services and is not responsible for compliance-related data handling. Websites that collect, process, or store such data, such as personal, financial, medical, or student information, must use third-party, client-managed storage solutions and maintain their own long-term archiving, backups, and compliance.
Server Log Analysis
Security investigations may require analysis of server access logs, which contain IP addresses and may include usernames or other account identifiers. PXM uses these logs only to investigate suspicious activity, identify unauthorized accounts, or determine how an account was compromised.
Backups
Routine website backups are provided by the client’s hosting provider and follow that provider’s retention policy. PXM may also keep its own archive copies of client websites, made periodically and before major updates, and stored securely for up to one year. For sites that collect sensitive or regulated data, PXM’s archive copies exclude form submissions and other sensitive records. These archive copies are intended for restoring the website and are not a backup of client data. Clients are responsible for backing up and retaining their own data through their hosting provider or IT staff.
Form Data Retention
Clients whose websites store form submissions are responsible for setting a retention period for that data, consistent with their records retention obligations. PXM will configure automatic deletion or anonymization of stored entries to match the client’s written direction. PXM does not delete stored submissions without written authorization from the client. Until a retention period is provided, entries remain stored under the form plugin’s default settings, and responsibility for that data remains with the client.
Use of AI Tools
PixelMongers may use AI tools to assist with drafting, coding, troubleshooting, and security analysis. All AI-assisted work is reviewed by PXM staff before delivery. PXM uses AI services under commercial terms that do not permit client inputs to be used for model training, and does not enter form submissions or other stored sensitive records into AI tools.
Security investigations may involve AI-assisted analysis of server access logs, which contain IP addresses and may include usernames or other account identifiers.
PXM does not enable AI features in plugins, themes, or third-party services on client sites without the client’s written approval.
For State of Oklahoma agencies, PXM follows the State of Oklahoma AI Policy and any AI-related terms in Statewide Contract SW0135. AI-assisted analysis of logs or site data is performed only as permitted by that policy and with agency approval where required.
Hosting Compliance Requirements
Clients are responsible for selecting a hosting environment that meets appropriate compliance and security standards:
- Payment processing requires PCI DSS-compliant hosting.
- Sensitive or regulated data (e.g., health, education, government) must be hosted on platforms meeting standards like SOC 2 Type II or HIPAA compliance.
- Hosting must include SSL, backups, secure access, and compatibility with WordPress.
PXM does not provide hosting directly but offers agency-managed hosting for qualifying clients and assists in third-party setup or migration.
Projects subject to FERPA, HIPAA, or CJIS must address compliance through a separate scope of work or agreement before services begin.
Limitation of Liability
PixelMongers is not liable for indirect, incidental, or consequential damages including data loss or downtime. Liability for any claim is limited to the total fees paid to PXM in the prior 12 months.
PXM is responsible for WordPress updates covered under maintenance but not for server-level or hosting-related vulnerabilities. In such cases, PXM will notify or assist the hosting provider as appropriate.
In the event of a breach, PXM will cooperate in good faith to assist with investigation, recovery, and restoration and may coordinate with relevant insurance procedures if applicable.
Force Majeure
PixelMongers shall not be held liable for any delay or failure to perform its obligations under this agreement due to events beyond its reasonable control. This includes, but is not limited to, acts of God, natural disasters, labor disputes, internet or power outages, pandemics, acts of government, or other unforeseen circumstances that prevent performance. In such cases, PixelMongers will resume services as soon as reasonably practicable.
Governing Law
This agreement shall be governed by and construed in accordance with the laws of the State of Oklahoma, without regard to conflict of law principles.
Changes to This Agreement
PixelMongers may update this SLA from time to time. Updates apply to existing maintenance plans at the start of the next renewal period. The current version is linked on renewal invoices and notices, and renewing a plan, paying a renewal invoice, or issuing a renewal purchase order constitutes acceptance of the terms in effect at that time.
For State of Oklahoma agencies, Statewide Contract SW0135 and the agency’s purchase order govern if they conflict with these terms.
Agreement Acceptance
By purchasing a PXM maintenance plan, whether through payment, invoice approval, or the issuance of a purchase order, the Client agrees to the terms outlined in this Service Level Agreement. For state agencies, a valid purchase order serves as authorization to begin services. For all other clients, payment of the first invoice constitutes acceptance of these terms. Signed agreements are not required unless otherwise specified.