Service Level Agreement (SLA) — Template
[LEGAL REVIEW REQUIRED before customer issuance]
This document is a template only. Per-customer SLAs are negotiated and signed separately. Contact sales for tailored terms. Do not issue to a customer without prior review by Noxys legal counsel.
Disclaimer. This document is intended as a starting point for negotiation. Final SLA terms are agreed per contract between Noxys Security SAS ("Noxys") and the Customer. This template is not legal advice — please review with your own legal counsel before signing.
Live availability metrics are published on the Noxys status page (
statut.noxys.cloud, see MON-1).
1. Header
| Field | Value |
|---|---|
| Version | 1.1 |
| Effective Date | to be filled at contract signature |
| Service Provider | Noxys Security SAS, 75 Boulevard Haussmann, 75008 Paris, France |
| Customer | to be filled at contract signature |
| Master Agreement | Noxys Terms of Service (separate document) |
| Review Cadence | Annual, or upon material service change |
2. Service Definitions
This SLA applies to the following Noxys services ("the Service"):
| Component | Description | Endpoint |
|---|---|---|
| Console | Admin web application (tenant management, policy authoring, audit log) | app.noxys.cloud |
| API | REST API for integrations and SDK consumers | api.noxys.cloud |
| Browser Extension | Chrome / Edge / Firefox / Safari extension enforcing policies in-browser | distributed via stores |
| Endpoint Agent | Native agent for managed devices | distributed via MDM / installer |
| Cloud Proxy | Optional egress proxy for non-browser AI traffic | proxy.noxys.cloud |
In scope for uptime targets: Console, API, Cloud Proxy.
Out of scope: Browser Extension and Endpoint Agent availability depend on the Customer's device fleet. Beta / preview features and the public sandbox environment are excluded from all uptime and response targets.
3. Availability Commitment
Monthly availability is measured per calendar month against each component's primary endpoint, on a rolling 30-day window.
| Tier | Monthly Uptime Target | Maintenance Window | Status Page |
|---|---|---|---|
| Free | Best-effort, no SLA | At Noxys' discretion | Public |
| Pro | 99.5 % | Sundays 02:00–04:00 UTC, 48 h notice | Public |
| Enterprise | 99.9 % | Customer-coordinated, 7 d notice | Public + email |
Per ADR-010 the commercial tiers are Free (0 €, up to 8 users), Pro (12 €/user/month) and Enterprise (custom). The legacy Starter / Business tiers are deprecated.
4. Measurement
- Availability is measured monthly across the billing cycle.
- Measurement is performed by an independent external monitor (e.g. Pingdom, UptimeRobot, Datadog Synthetics) probing each endpoint from at least three geographic regions every 60 seconds.
- A "downtime minute" is any minute in which two consecutive probes from two distinct regions return HTTP 5xx, time out, or fail TLS handshake.
- Scheduled maintenance windows and excluded events (Section 9) do not count as downtime.
- Monthly availability is computed as
(total_minutes - downtime_minutes) / total_minutes × 100.
5. Service Credits (Pro and Enterprise)
If Noxys fails to meet the monthly uptime target, the Customer may request a service credit applied to the next invoice:
| Monthly Availability | Service Credit |
|---|---|
< 99.5 % (Pro target missed) | 5 % of monthly fee |
< 99.0 % | 10 % of monthly fee |
< 95.0 % | 25 % of monthly fee |
Service credits are the sole and exclusive remedy for SLA breaches. Credits do not apply to the Free tier. Credits are capped at 50 % of the monthly fee. Customers must claim credits within 30 days of the incident (see Section 10).
6. Incident Response SLA
Incidents are classified by severity at the time of triage. Severity levels are interchangeable with S1 / S2 / S3 / S4 notation used internally.
| Severity | Definition | Acknowledgement | Resolution Target | Update Cadence |
|---|---|---|---|---|
| S1 / P1 — Critical | Service unavailable for all users, data loss risk, or active security incident | < 1 h | < 4 h | Every 30 min |
| S2 / P2 — High | Major feature broken for multiple users (e.g. policy engine failure, auth outage) | < 4 h | < 24 h | Every 2 h |
| S3 / P3 — Medium | Partial degradation, workaround exists, or single-user impact | < 1 business day | < 5 business days | Daily |
| S4 / P4 — Low | Cosmetic, documentation, or non-blocking feature request | < 3 business days | Best-effort, no restore SLA | On status change |
Acknowledgement and resolution times are measured from the moment the incident is reported via an approved channel (Section 7).
7. Communication Channels & Escalation Matrix
| Tier | Primary Channel | Escalation Channel | Hours |
|---|---|---|---|
| Free | Community forum | — | Community-supported |
| Pro | support@noxys.eu | In-console support widget | Business hours, Mon–Fri 09:00–18:00 CET |
| Enterprise | Dedicated Slack Connect or email | Named TAM phone line, on-call rotation | 24 × 7 for S1 / S2 |
Shared channels (all tiers):
- Status page:
statut.noxys.cloud(real-time + historical, see MON-1). - Security incidents:
security@noxys.eu(PGP key on the trust center).
S1 incidents auto-escalate to the on-call engineering manager after the acknowledgement window. S1 incidents unresolved after the resolution target auto-escalate to the CTO.
8. Reporting
- A public status page (
statut.noxys.cloud) shows real-time and historical availability for all covered components. - Enterprise customers receive a monthly SLA report by email, listing uptime per component, incidents, and any credits owed. The report is also surfaced in the admin console (linked from the status page once MON-1 ships).
- Post-incident reports are published for any S1 incident within 5 business days of resolution.
9. Exclusions
The following events do not count as downtime and do not trigger indemnification:
- Force majeure — natural disasters, war, government action, internet backbone outages affecting major regions.
- Customer-induced — misconfiguration, unsupported integrations, exceeding documented quotas, abuse of the API.
- Scheduled maintenance announced per Section 3.
- Third-party dependencies outside Noxys' control (e.g. LLM provider outage, Cloudflare, AWS, OAuth providers) where Noxys has no commercially reasonable workaround.
- Beta / preview features explicitly labelled as such.
- Free tier — best-effort, no SLA.
10. Indemnification & Claims Process
- Submit a claim to
support@noxys.euwithin 30 days of the incident, citing the incident reference and affected period. - Noxys verifies the claim against the external monitor data and responds within 10 business days.
- Approved credits are applied to the next invoice. Credits cannot be redeemed for cash refunds.
- Service credits are the sole and exclusive remedy (Section 5).
Indemnification scale (recap): 5 % of the monthly fee per 0.1 % uptime miss beyond the tier target, capped at 50 % of the monthly fee for the affected month, applied to the next invoice.
11. Review Cadence
This SLA is reviewed annually or upon material change to the Service (new component, deprecation, infrastructure migration). Updates take effect on the next billing cycle following written notice to the Customer.
Related Documents
- AGENT-5 — CRA pre-assessment (
docs/compliance/cra/README.md) - ADR-010 — Pricing tiers (3 tiers: Free / Pro / Enterprise)
- MON-1 — Public status page (
statut.noxys.cloud) - Terms of Service — Master commercial agreement (separate document)
Appendix A — Change Log
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-05-10 | Noxys Security SAS | Initial template (CONTRIB-4 draft) |
| 1.1 | 2026-05-20 | Noxys Security SAS | SUPPORT-1 #344: legal-review banner, S1–S4 aliases, rolling 30-day window, indemnification recap, scope tightened to Enterprise-prospect handover |