← Trust Center
Policy

Service Level Agreement & Support Policy

SafeToOpen's uptime commitment, support severities and response targets, and service credits for business, government and MSP customers.

Applies to: Business, government, and MSP customers on paid plans · Classification: Public (referenced from customer agreements) · Version: 1.0 — July 2026

Service commitment

SafeToOpen will provide the services with reasonable skill and care, 24 hours a day, 7 days a week, excluding planned maintenance.

Availability

Monthly uptime target: 99.5% for the SafeToOpen cloud detection services and API, measured per calendar month, excluding planned maintenance and factors outside our reasonable control.

The service is designed to fail safe: if the SafeToOpen cloud is temporarily unreachable, the browser extension continues to provide local protection and never blocks normal browsing. A cloud outage degrades detection of brand-new threats but does not interrupt customers' work.

Planned maintenance

Planned maintenance is performed outside New Zealand business hours wherever possible, with at least 5 business days' notice by email for potentially disruptive work.

Support

ItemCommitment
Channel[email protected]
HoursMonday–Friday, 9:00–17:00 NZT, excluding NZ public holidays
LanguageEnglish

Response targets by severity:

SeverityDefinitionFirst responseUpdate cadenceTarget resolution
Sev 1 — CriticalService unavailable for all users, or a security incident affecting customer data4 business hoursEvery 4 business hoursWorkaround within 24 hours
Sev 2 — HighMajor function degraded; no workaround8 business hoursDaily3 business days
Sev 3 — MediumMinor function degraded; workaround exists2 business daysNext scheduled release
Sev 4 — LowQuestion, cosmetic issue, feature request5 business daysConsidered for roadmap

False positives (a legitimate page incorrectly flagged) are treated as Sev 2 for business customers: reviewed by a person, with corrections propagated automatically to all users.

Service credits

If monthly uptime falls below target, affected customers may claim a service credit: below 99.5% — 10% of that month's fee; below 99.0% — 25%; below 95.0% — 50%. Claims must be made within 30 days of month end to [email protected]. Credits are the sole and exclusive remedy for availability shortfalls, are capped at 100% of the monthly fee, and do not apply to failures caused by the customer's environment, third-party services, or force majeure.

Security incidents and breach notification

Security incidents affecting customer data follow our Incident Response Policy: notification without undue delay and no later than 72 hours after confirmation of a breach, with known impact, remediation steps, and a named contact.

Data return on exit

On termination, customers may request export of their configuration and data in a standard format within 30 days; SafeToOpen then deletes customer data in line with the Data Retention & Deletion Policy summary.

Review

This SLA is reviewed annually and versioned; material changes are notified to customers 30 days in advance.

Document control: v1.0 · Approved by the Managing Director · Next review: July 2027. Related: Terms of Service (safetoopen.com/en/terms) · DPA · Policy Summaries · Security Overview.

Questions from your security team?

We answer reviewer questions directly and provide the full security review pack under NDA — typical turnaround one business day.

Contact [email protected]