Service Level Agreement

Formal uptime, support, and recovery commitments for CertiGuard GRC platform customers.

Effective Date: 8 September 2026 · Version 2.0

1. Service Uptime Commitment

CertiGuard GRC commits to a monthly uptime of 99.9% for the production platform, excluding scheduled maintenance windows. Uptime is measured as the percentage of minutes the web application and API endpoints respond successfully to health-check requests.

99.9%

Uptime Target

Monthly

~43 min

Max Downtime

Per month

24/7

Monitoring

Real-time

Public

Status Page

Live updates

2. Support Response & Resolution SLAs

All support tickets are triaged by severity. Response times are measured from ticket submission to first human response from the CertiGuard support team. Business hours are 08:00–17:00 Africa/Johannesburg, Monday–Friday.

SeverityDescriptionFirst ResponseResolution TargetUpdates
CriticalProduction service completely unavailable or security breach in progress.15 minutes4 hoursEvery 60 minutes
HighMajor functionality impaired with no workaround available.1 hour8 hoursEvery 2 hours
MediumPartial impairment with workaround available.4 business hours2 business daysDaily
LowCosmetic issue or feature request with no operational impact.1 business dayBest effortAs needed

3. Incident Notification

Detection & Triage

Incidents detected by automated monitoring or customer reports are triaged within 15 minutes of detection.

Customer Notification

Affected customers are notified by email within 30 minutes of incident confirmation for Critical and High severity events.

Status Updates

Regular status updates are posted to the public status page and emailed to affected customers at the cadence defined by severity.

Post-Incident Report

A detailed root-cause analysis and remediation plan is delivered within 5 business days of incident resolution.

4. Backup & Disaster Recovery

Recovery Point Objective (RPO)

≤ 15 min

Maximum potential data loss in a disaster scenario. Database snapshots are taken every 15 minutes.

Recovery Time Objective (RTO)

≤ 4 hours

Maximum time to restore full service availability after a declared disaster.

• Database backups are encrypted at rest (AES-256) and retained for 35 days.

• Evidence and document storage is replicated across multiple availability zones.

• Disaster recovery procedures are tested quarterly with documented results.

• Immutable audit trail records (IGGL) are protected against tampering and deletion.

5. Scheduled Maintenance

Scheduled maintenance windows are conducted during low-traffic periods (Sundays 02:00–05:00 Africa/Johannesburg). Customers are notified at least 72 hours in advance for any maintenance that may cause brief service interruption. Emergency maintenance may be conducted with shorter notice for critical security patches, with notification provided as early as possible.

6. Service Credits

If monthly uptime falls below 99.9%, customers are eligible for service credits applied to the next billing cycle:

Monthly UptimeService Credit
99.0% – 99.89%10% of monthly fee
95.0% – 98.99%25% of monthly fee
Below 95.0%50% of monthly fee

Support Contact

For SLA-related queries or to report a service incident: