Terms of Service / Service Level Agreement

Service Level Agreement

Effective Date: August 22, 2026

Version 2.1

1. Applicability

This Service Level Agreement ("SLA") applies to all paid subscription tiers (Pro, Enclave, and Sovereign). OPEN-tier accounts receive best-effort availability with no uptime commitment or credit entitlement.

Sovereign engagements may include custom SLA terms negotiated in the Statement of Work. Where custom terms conflict with this SLA, the Statement of Work governs.

2. Availability Target

99.5%

Monthly uptime target (excludes planned maintenance)

Permitted downtime: 3 hours 39 minutes per month

Availability is measured from the health endpoint (/api/v1/health) using HTTP 200 responses over rolling 30-day windows. The platform runs on a single-region deployment with automated process recovery. Infrastructure availability is backed by the hosting provider's own SLA.

3. Evidence Continuity

Platform downtime does not stop evidence generation.

The SWT3 SDK computes SHA-256 hashes locally on your infrastructure and buffers witness anchors in memory. If the platform is temporarily unreachable, no evidence is lost and no customer system is affected. Anchors flush automatically when connectivity resumes.

This architecture means the platform is not in the critical path of your AI system. An outage affects dashboard visibility and verification lookups, not your application's operation or your compliance evidence pipeline.

At Clearing Level 3 (Classified), the SDK transmits only numeric factors and hashed model identifiers -- no plaintext model names, no provider metadata. The platform still receives and stores these minimal anchors, but the data carries no identifying content beyond one-way hashes.

For air-gapped deployments (available under Sovereign engagements), anchors are stored entirely within the customer's infrastructure via offline .pulse bundle files. The platform does not receive or store any witness data. In this configuration, platform availability is irrelevant to evidence production -- the customer retains full custody.

4. Covered Services

  • Axiom Sovereign Engine dashboard (sovereign.tenova.io)
  • Witness ingestion API (/api/v1/witness, /api/v1/witness/batch)
  • Public verification endpoint (/verify)
  • Merkle proof API (/api/v1/merkle)
  • Compliance Passport export (/api/v1/passport/export)

5. Support Tiers

OpenProEnclaveSovereign
ChannelDocs + guidesEmailPriority emailDirect access
HoursSelf-serveBusiness hours (US Eastern)Business hours (US Eastern)Business hours (US Eastern)
Response target--1 business daySame business day1 business day
SLA creditsNoYesYesYes
Uptime targetBest effort99.5%99.5%Per SOW

All tiers receive access to the full guide library (219 documents), SDK documentation, API reference, and troubleshooting FAQ. Support inquiries: support@tenovaai.com.

6. Incident Severity and Response

SeverityDescriptionResponseResolution target
CriticalComplete service outage or data integrity breach1 business dayBest effort, typically 2 business days
HighPartial service degradation or API errors affecting ingestion1 business day2 business days
MediumNon-critical feature unavailable (exports, dashboard page)2 business days5 business days
LowCosmetic issues, documentation errors5 business daysNext release

Response and resolution targets are measured in business hours (Monday through Friday, 9:00 AM to 6:00 PM US Eastern, excluding US federal holidays). Outside business hours, automated process recovery handles application-level failures. Infrastructure-level incidents are covered by the hosting provider's monitoring and SLA.

7. SLA Credits

If monthly availability falls below the target for Pro or Enclave subscribers, a service credit is applied to the next invoice:

Monthly availabilityService credit
99.0% to 99.49%5% of monthly fee
Below 99.0%10% of monthly fee
  • Credits are capped at 25% of the monthly subscription fee
  • Credits are the sole and exclusive remedy for availability shortfalls
  • To claim a credit, email support@tenovaai.com within 30 days of the affected month with the dates and times of observed unavailability
  • Credits do not apply to OPEN-tier accounts or Sovereign engagements with custom SLA terms

8. Recovery Objectives

Recovery Time Objective (RTO)

8 hours

From incident detection to service restoration (business hours)

Recovery Point Objective (RPO)

24 hours

Maximum data loss window for application-layer state. Witness anchors in the ledger are not affected.

9. Planned Maintenance

  • Maintenance window: Tuesdays 02:00 - 04:00 UTC
  • 24 hours advance notice for scheduled maintenance
  • Frequency: as needed, typically bi-weekly for deployments
  • Planned maintenance is excluded from availability calculations
  • Emergency patches may be applied outside the maintenance window with best-effort advance notice

10. Backup Schedule

  • Daily encrypted backup at 02:00 UTC (AES-256, 7-day retention)
  • Weekly encrypted backup on Sundays (AES-256, 4-week retention)
  • Database: Supabase managed continuous backup with point-in-time recovery
  • Witness anchors reside in Supabase managed infrastructure and are not affected by application-layer backup gaps

11. Data Location and Residency

What the platform stores

The platform stores one-way SHA-256 cryptographic hashes derived from numeric compliance factors (latency, token count, confidence score), verdict metadata, and account-level information (email, organization name). At Clearing Level 1 and above, raw prompts and model responses never leave your infrastructure.

Current hosting locations

ServiceProviderLocation
Application and APIVultr (The Constant Company)United States (New Jersey)
Database and authenticationSupabase (AWS)United States (us-east-1)
Payment processingStripeUnited States

International transfers

For transfers of account-level personal data from the European Economic Area, the United Kingdom, or Switzerland, the transfer mechanisms described in the Data Processing Agreement apply: Standard Contractual Clauses (Module 2) and the EU-US Data Privacy Framework where applicable to sub-processors.

Witness anchors consist solely of irreversible cryptographic hashes and numeric factors. These cannot identify any natural person and fall outside the scope of personal data under GDPR Recital 26. At Clearing Level 3, anchor content is further minimized to numeric factors and hashed model names. In air-gapped Sovereign deployments, the platform receives no witness data -- the customer retains full custody.

EU-resident deployment

EU-resident hosting is available as part of Sovereign engagements where a customer requires data to remain within the European Economic Area. Contact support@tenovaai.com to discuss requirements.

12. Exclusions

The following are excluded from availability calculations and credit eligibility:

  • Planned maintenance within the designated maintenance window
  • Force majeure events (natural disasters, government actions, pandemic)
  • Supabase managed service outages (covered by Supabase's own SLA)
  • Third-party dependency failures (package registries, DNS providers)
  • Client-side network, firewall, or DNS issues
  • Actions or inactions by the subscriber that cause service degradation

13. Incident Reporting

To report a service incident or inquire about SLA compliance, contact support@tenovaai.com with your tenant ID and a description of the observed issue. The platform status page is available at /status.

14. Modifications

TeNova may update this SLA to reflect changes in infrastructure, support capacity, or service scope. Material changes will be communicated at least 30 days before taking effect. The current version is always available at this URL.

This SLA is incorporated by reference into the Terms of Service. See also: Data Processing Agreement | Clearing Addendum | Security.