Skip to content

Support

HolonomiX supports the HX-Provenance appliance, Vertex AI adapter, Marketplace deployment package, receipt lifecycle, and release-matched verification tools supplied with HX-Provenance for Vertex AI.

Contact

Request Channel
Product support support@holonomx.com
Security-sensitive issue security@holonomx.com
Legal, order, or commercial question HolonomiX contact

Response targets, support hours, and service levels are governed by the applicable Marketplace order, private offer, or written agreement. This page does not create a separate SLA.

Supported scope

Product support covers:

  • Marketplace deployment, upgrade, appliance replacement, retained-data removal, and intentional purge procedures;
  • appliance first boot, bootstrap readiness, manifest integrity, health, and service operation;
  • private VPC, DNS, verified TLS, Direct VPC egress, and IAP paths created by the package;
  • four-secret publication, coordinated active material, and documented rotation inputs;
  • Cloud Run adapter and Eventarc generation-bound packet delivery;
  • bounded packet validation and deterministic rejection evidence;
  • receipt issuance and independent adapter verification;
  • create-only Cloud Storage receipt evidence and BigQuery MERGE indexing;
  • appliance and release-matched offline verification;
  • bounded evidence-bundle export and verification; and
  • product defects or questions about documented configuration.

The following remain customer or provider responsibilities:

  • Google Cloud account, billing, quota, and organization-policy administration;
  • Vertex AI model selection, model behavior, prompt engineering, and safety controls;
  • packet-producing application code and producer-commitment truthfulness;
  • customer IAM outside the package's documented roles;
  • retention, legal hold, monitoring, and incident policy; and
  • third-party systems, source data, and downstream use of receipts.

Before opening a request

Use the focused guides first:

Gather:

  • organization name and authorized contact;
  • Google Cloud project ID;
  • Marketplace order or deployment reference, when available;
  • product version, appliance image identity, and deployment prefix;
  • region, zone, and affected resource names;
  • source bucket, object name, and generation;
  • event_key, receipt URI, and receipt object generation, when available;
  • UTC timestamps and relevant request or trace IDs;
  • expected and observed behavior;
  • minimal reproduction steps; and
  • sanitized status and logs limited to the relevant time window.

Safe first diagnostics

export PROJECT_ID="your-project-id"
export REGION="us-central1"
export ZONE="us-central1-a"
export APPLIANCE="deployment-appliance-name"
export ADAPTER_SERVICE="deployment-adapter-service"
export EVENTARC_TRIGGER="deployment-eventarc-trigger"

gcloud compute instances describe "$APPLIANCE" \
  --project="$PROJECT_ID" --zone="$ZONE" \
  --format='yaml(name,status,hostname,networkInterfaces,shieldedInstanceConfig)'

gcloud compute ssh "$APPLIANCE" \
  --project="$PROJECT_ID" --zone="$ZONE" --tunnel-through-iap \
  --command='sudo systemctl status hx-provenance.service nginx --no-pager;
    sudo journalctl -u hx-provenance.service --since "30 minutes ago" --no-pager;
    sudo journalctl -t hx-vertex-ai-bootstrap --since "30 minutes ago" --no-pager'

gcloud run services describe "$ADAPTER_SERVICE" \
  --project="$PROJECT_ID" --region="$REGION"

gcloud run services logs read "$ADAPTER_SERVICE" \
  --project="$PROJECT_ID" --region="$REGION" --limit=100

gcloud eventarc triggers describe "$EVENTARC_TRIGGER" \
  --project="$PROJECT_ID" --location="$REGION"

Review and redact the output before transmission.

Do not send through ordinary email

Do not send:

  • API keys, Secret Manager values, or authorization headers;
  • ML-DSA signing keys, CA private keys, or TLS private keys;
  • raw regulated data or confidential prompt, source, output, or packet content;
  • unsanitized receipts or evidence bundles;
  • full Terraform state; or
  • logs containing credentials or customer payloads.

Use a secure transfer channel agreed with HolonomiX when support requires sensitive evidence. HolonomiX support will not ask you to weaken TLS, disable signature pinning, add a public VM IP, or transmit a private signing key.

Security incidents

For a suspected vulnerability, exposed key, forged receipt, or unexpected signer-fingerprint change:

  1. stop affected packet producers;
  2. preserve logs, source tuples, evidence generations, index rows, and resource metadata;
  3. restrict access without deleting evidence;
  4. record the last trusted public key, fingerprint, image identity, and receipt;
  5. do not rotate or destroy evidence until the incident owner approves the sequence; and
  6. contact security@holonomx.com privately.

Public disclosure policy: https://holonomx.com/security

Return to the deployment and operations guide.