Reliability
Service levels
What we aim for, how it is measured, and why we are not calling it an SLA yet.
Last reviewed 31 August 2026
These are objectives, not a contractual SLA. We do not currently offer service credits, and we would rather say so than sell a commitment we have not yet built the operational maturity to honour. When the operating record supports a real SLA we will publish one; until then these are the targets we hold ourselves to and measure against.
| Objective | Target | How it is measured |
|---|---|---|
| Gateway availability | 99.5% monthly | Measured from the ingress. Excludes announced maintenance, which we announce on the status page. |
| Decision path latency | p95 under 250 ms | Fabric overhead only -- the time we add on top of the upstream service, not the upstream's own response time. |
| Evidence durability | No acknowledged decision record lost | A decision is acknowledged only after it is committed. Backups run daily and restores are tested. |
| Security report acknowledgement | 3 business days | See the disclosure policy. |
| Status page accuracy | Updated within 15 minutes of a confirmed incident | Including incidents nobody reported. |
What you can see for yourself
The status page reports live health, and GET /slo returns the measured numbers behind these targets rather than the targets themselves — including when we are missing one. A status page that only ever shows green is a status page nobody should believe.
Maintenance
Planned maintenance is announced on the status page and the changelog before it happens. The hosted deployment runs multiple gateway replicas behind one ingress, so routine deploys do not require a window.
The limits of this, stated plainly
Single region, single hosting provider, and a small team rather than a follow-the-sun on-call rota. That covers process failure, not site failure, and it means our realistic response time outside working hours is slower than a large vendor's. Both are on the gaps page and on the roadmap. The self-hosted deployment is unaffected by any of it — it runs on your infrastructure with your availability.