How we operate

Enterprise SaaS you can inspect — from the inside out.

Most vendors ask you to trust them. We publish our runbook. BorakDesk runs a full ITIL v4 operations layer internally — the same Incident, Problem, Change, and Service management practices that Google SRE, Netflix, and Bloomberg use — and every postmortem for a customer-impacting incident is public.

Live status page →Read our postmortems →
The four pillars

ITIL 4 practices, actually operationalized.

Not a slide deck. A working system with data behind every claim.

🚨
Incident Management
ITIL 4 · Service Value Chain

Every service disruption is declared with a SEV1–SEV4 classification, an Incident Commander, timestamps for detect→acknowledge→mitigate→resolve, and a live timeline visible to affected customers on the public status page. SLA breach detection runs on a 15-minute cron; new CRITICAL incidents fan out to Slack instantly.

  • SEV1–SEV4 severity model
  • Incident Commander assigned per incident
  • MTTA / MTTM / MTTR tracked per severity
  • Auto-fires Slack alerts on CRITICAL + breach
🔬
Problem Management
ITIL 4 · Continual Improvement

Every published postmortem creates a Problem record with hypothesis → root cause → workaround → resolution status. Postmortem action items become tracked ProblemActionItems with a named owner and a due date. Known Errors are surfaced when a workaround exists but the root cause remains open.

  • Hypothesis → root cause → known error workflow
  • Action items with assignee + due date
  • Cross-linked to originating incidents
  • Never “tribal knowledge” — always in the record
🔧
Change Enablement
ITIL 4 · Service Management

Every production change is a Change record: type (Standard / Normal / Emergency), risk × impact matrix, required approvals, backout plan, planned window, actual outcome. Freeze windows block high-risk changes during holidays and blackout periods. Emergency changes require post-hoc written justification.

  • CAB matrix keyed on Risk × Impact
  • Backout plan required — no shortcuts
  • Change freeze windows honored
  • Every change auditable in a SOC 2 CSV
📚
Service Configuration
ITIL 4 · Foundation

Every service BorakDesk operates (Email Delivery, AI Generation, Auth, Billing, per-region APIs, etc.) is catalogued with a Service Owner, RACI matrix (Responsible / Accountable / Consulted / Informed), SLA tier (P1/P2/P3), and a public-facing status. Incidents auto-flip service status on the public page — no manual step.

  • Service catalog with Service Owner per row
  • RACI matrix per service
  • Auto service-status derivation from incidents
  • SLA tier and target uptime published
Receipts, not slides

What we do differently from other vendors.

Public postmortems

Every SEV1 and SEV2 incident gets a public postmortem — 5-Whys root cause, timeline, what went well, what went poorly, and concrete prevention commitments (each backed by a tracked action item). Not filed away in an internal Confluence.

Read postmortems →
Live public status page

Real service status (auto-derived from incidents), live incident timeline, upcoming maintenance, 14-day incident history. Subscribe to email updates when an incident opens, updates, or resolves.

Status page →
ITIL 4 maturity scorecard

We self-assess maturity quarterly across all 34 ITIL 4 practices — not as marketing, but as a real internal discipline. Willing to share the current scorecard with any Enterprise or Enterprise Plus prospect.

Talk to sales →
Auditor-ready evidence CSVs

One click generates a SOC 2 CC7.1 (Change Management) or CC7.3 (Incident Management) evidence bundle — CSV your auditor can drop into their workpapers. Same data your team sees; nothing polished up.

Security & compliance →
On-call rotation transparency

Enterprise customers see the on-call rotation schedule, escalation policy timing (primary → secondary → manager), and the human who is on call right now for the services they depend on. No black box.

Talk to sales →
Change → Incident correlation

Every incident is automatically correlated against Changes deployed in the 24 hours prior — ranked by service overlap and time proximity. Root causes take minutes, not hours, to identify.

How it works
Why this matters for you

Vendors either publish their runbook — or they hide behind it.

Every marketing SaaS on the planet claims “enterprise-grade reliability.” We think enterprise-grade is a measurable, auditable claim — not an adjective. So we operationalized it: ITIL 4 Incident, Problem, Change, and Service Management from day one; a public status page that customers can subscribe to; postmortems that anyone can read; and CSAT-quality evidence CSVs any auditor can consume.

When something breaks — and things break at every vendor — we tell you exactly what happened, what we did about it, and what we're doing so it never happens again. That's the standard. It's also the standard your legal team wants, your security team wants, and your board wants.

And it's why BorakDesk is the marketing platform enterprises actually trust for the workloads that matter — HIPAA-regulated patient outreach, financial services drip campaigns, real-estate transaction flows.

See the operational rigor yourself.

The status page is live, the postmortem library is public. Ask us for the ITIL 4 maturity scorecard, the SOC 2 evidence bundle, and the on-call rotation on any Enterprise call.

Live status page →Security & compliance →Talk to sales →