Support from the people who built it.
You own the platform. That doesn't mean you're on your own with it. Support requests reach the engineers who designed your environment — there is no first-line tier reading from a script, because there is no first-line tier.
Where to send it
Pick the right channel
Three routes. Picking the right one is the fastest way to get an answer.
Report a Security Incident
Active breach or urgent incident on a WhyCrew-built platform. Monitored 24/7 and answered by an engineer. Do not use the general form below for this.
incident@whycrew.comPlatform Support Request
Upgrades, detection tuning, a runbook question, a new integration, or anything else about a platform we built. Goes to the engineering team, not a ticket queue.
Open a Support RequestGeneral Inquiry
Not a client yet, or asking about a new engagement rather than an existing platform. The main contact page routes those.
Go to ContactWhat support covers
Optional, not a dependency
Ownership is the whole point of the model, so it's worth being explicit about where support sits relative to it.
Covered by an optional retainer
Version upgrades, detection tuning, new SOAR playbooks, additional integrations, and engineering support on a running platform. Optional means optional — the platform, infrastructure, and roadmap are yours from day one, with no mandatory ongoing fees.
Yours to run without us
Every engagement hands over source code, infrastructure, API documentation, runbooks, and hands-on training. Your team can operate and extend the platform entirely in-house, and plenty do.
Not offered standalone
Emergency incident response is available to existing clients running a platform we built. It isn't offered as a first-time, standalone engagement — we can't respond well inside an environment we've never seen.
Raise a request
Tell us what's happening
Pre-routed to platform support. For an active incident, use the 24/7 line above instead — it's monitored, this form is read during business hours.
What to include
- Which platform or environment the issue affects
- What you expected to happen, and what happened instead
- When it started, and whether anything changed around that time
- Relevant log lines, alert IDs, or playbook names — redacted as your policy requires
- How urgent it is for you, in your own words
Frequently asked questions
Support questions
Teams running a platform WhyCrew built. The 24/7 incident line and platform support requests are both for existing clients. If you're evaluating a new engagement, the contact page is the right route.
The incident line is monitored 24/7. General inquiries and platform support requests get a reply within one business day, from an engineer rather than a first-line agent.
No. An optional retainer covers upgrades, detection tuning, and ongoing engineering support, but there are no mandatory ongoing fees and no contract you're required to sign to keep running the platform.
That's the intended end state. Handover includes source code, infrastructure, API documentation, runbooks, and training specifically so your team can run and extend the platform without us.
Not as a support engagement. What we can do is assess it — a migration or architecture review is a normal starting point, and that route runs through the contact page.
Not a support question
Looking at a new build?
If you're scoping something new rather than running something we built, start here instead.
Custom SIEM & SOAR · AI SOC Automation · MSSP Engineering Partner · NIS2 & DORA Compliance