Formal uptime, support, and recovery commitments for CertiGuard GRC platform customers.
Effective Date: 8 September 2026 · Version 2.0
CertiGuard GRC commits to a monthly uptime of 99.9% for the production platform, excluding scheduled maintenance windows. Uptime is measured as the percentage of minutes the web application and API endpoints respond successfully to health-check requests.
99.9%
Uptime Target
Monthly
~43 min
Max Downtime
Per month
24/7
Monitoring
Real-time
Public
Status Page
Live updates
All support tickets are triaged by severity. Response times are measured from ticket submission to first human response from the CertiGuard support team. Business hours are 08:00–17:00 Africa/Johannesburg, Monday–Friday.
| Severity | Description | First Response | Resolution Target | Updates |
|---|---|---|---|---|
| Critical | Production service completely unavailable or security breach in progress. | 15 minutes | 4 hours | Every 60 minutes |
| High | Major functionality impaired with no workaround available. | 1 hour | 8 hours | Every 2 hours |
| Medium | Partial impairment with workaround available. | 4 business hours | 2 business days | Daily |
| Low | Cosmetic issue or feature request with no operational impact. | 1 business day | Best effort | As needed |
Detection & Triage
Incidents detected by automated monitoring or customer reports are triaged within 15 minutes of detection.
Customer Notification
Affected customers are notified by email within 30 minutes of incident confirmation for Critical and High severity events.
Status Updates
Regular status updates are posted to the public status page and emailed to affected customers at the cadence defined by severity.
Post-Incident Report
A detailed root-cause analysis and remediation plan is delivered within 5 business days of incident resolution.
Recovery Point Objective (RPO)
≤ 15 min
Maximum potential data loss in a disaster scenario. Database snapshots are taken every 15 minutes.
Recovery Time Objective (RTO)
≤ 4 hours
Maximum time to restore full service availability after a declared disaster.
• Database backups are encrypted at rest (AES-256) and retained for 35 days.
• Evidence and document storage is replicated across multiple availability zones.
• Disaster recovery procedures are tested quarterly with documented results.
• Immutable audit trail records (IGGL) are protected against tampering and deletion.
Scheduled maintenance windows are conducted during low-traffic periods (Sundays 02:00–05:00 Africa/Johannesburg). Customers are notified at least 72 hours in advance for any maintenance that may cause brief service interruption. Emergency maintenance may be conducted with shorter notice for critical security patches, with notification provided as early as possible.
If monthly uptime falls below 99.9%, customers are eligible for service credits applied to the next billing cycle:
| Monthly Uptime | Service Credit |
|---|---|
| 99.0% – 99.89% | 10% of monthly fee |
| 95.0% – 98.99% | 25% of monthly fee |
| Below 95.0% | 50% of monthly fee |
For SLA-related queries or to report a service incident: