Service commitment
SafeToOpen will provide the services with reasonable skill and care, 24 hours a day, 7 days a week, excluding planned maintenance.
Availability
Monthly uptime target: 99.5% for the SafeToOpen cloud detection services and API, measured per calendar month, excluding planned maintenance and factors outside our reasonable control.
The service is designed to fail safe: if the SafeToOpen cloud is temporarily unreachable, the browser extension continues to provide local protection and never blocks normal browsing. A cloud outage degrades detection of brand-new threats but does not interrupt customers' work.
Planned maintenance
Planned maintenance is performed outside New Zealand business hours wherever possible, with at least 5 business days' notice by email for potentially disruptive work.
Support
| Item | Commitment |
|---|---|
| Channel | [email protected] |
| Hours | Monday–Friday, 9:00–17:00 NZT, excluding NZ public holidays |
| Language | English |
Response targets by severity:
| Severity | Definition | First response | Update cadence | Target resolution |
|---|---|---|---|---|
| Sev 1 — Critical | Service unavailable for all users, or a security incident affecting customer data | 4 business hours | Every 4 business hours | Workaround within 24 hours |
| Sev 2 — High | Major function degraded; no workaround | 8 business hours | Daily | 3 business days |
| Sev 3 — Medium | Minor function degraded; workaround exists | 2 business days | — | Next scheduled release |
| Sev 4 — Low | Question, cosmetic issue, feature request | 5 business days | — | Considered for roadmap |
False positives (a legitimate page incorrectly flagged) are treated as Sev 2 for business customers: reviewed by a person, with corrections propagated automatically to all users.
Service credits
If monthly uptime falls below target, affected customers may claim a service credit: below 99.5% — 10% of that month's fee; below 99.0% — 25%; below 95.0% — 50%. Claims must be made within 30 days of month end to [email protected]. Credits are the sole and exclusive remedy for availability shortfalls, are capped at 100% of the monthly fee, and do not apply to failures caused by the customer's environment, third-party services, or force majeure.
Security incidents and breach notification
Security incidents affecting customer data follow our Incident Response Policy: notification without undue delay and no later than 72 hours after confirmation of a breach, with known impact, remediation steps, and a named contact.
Data return on exit
On termination, customers may request export of their configuration and data in a standard format within 30 days; SafeToOpen then deletes customer data in line with the Data Retention & Deletion Policy summary.
Review
This SLA is reviewed annually and versioned; material changes are notified to customers 30 days in advance.
Document control: v1.0 · Approved by the Managing Director · Next review: July 2027. Related: Terms of Service (safetoopen.com/en/terms) · DPA · Policy Summaries · Security Overview.