Service Commitments
Last updated August 7, 2026
What we commit to today, and which numbers we deliberately withhold until they are measured — with the reason, in both directions.
What this page is
Most SLA pages lead with an uptime percentage. Ours does not, because we have not yet measured the things that make such a number honest — and a commitment we have not tested is a commitment we would eventually breach. What follows is split accordingly: the commitments we make because the system enforces them, and the numbers we withhold until they are measured.
Commitments in force
Monitoring: an automated probe checks the production application and its health endpoint every 30 minutes, independently of our own infrastructure, and failures alert us. This page will not claim 24/7 on-call — there is none — but an outage does not wait for a customer to report it.
Deletion: removing a document, project, or organization takes effect immediately from every live path, hard-purges after a 14-day undo window, and clears from backups within 30 days as they age out. These numbers are published because the purge job enforces them.
Billing failure: 14 days of full access to fix payment, then read-only. Reads always work, exports always work, and data is never deleted over a billing problem. Enforced by the entitlement system, not by policy.
Processing failures are explicit: a document run that fails surfaces an error and can be re-queued; it does not silently vanish. Processing time itself is stated as no commitment at all — extraction of a large scanned book takes hours by nature, and depends on document quality we do not control.
Incidents: affected account owners are notified by email without undue delay, and a suspected cross-tenant exposure is treated as a disclosure event from the first minute — suspicion starts the clock, not confirmation.
Backups: automatic, daily, with 30-day retention. The recovery targets they imply are exactly what the next section declines to publish.
Numbers we deliberately do not publish yet
Uptime percentage: publishing 99.x% is only honest with an operational history behind it and someone on call when it slips. We have monitoring; we do not yet have the history or the rotation, so the number waits.
Recovery time and recovery point (RTO/RPO): no restore has been drilled at production data volume, and whether uploaded files share the database’s backup posture is not yet confirmed. A recovery figure before that drill would be a design estimate wearing a contract’s clothes.
Tiered support response times: every customer currently reaches the founding team directly, which in practice is faster than a tiered matrix — but "in practice" is not a commitment, so no matrix is printed here until one can be honored on bad weeks too.
When these numbers arrive, they arrive here, with the measurement method next to them.
Your side of it
Supply legible documents — a PDF corrupted in transfer (saved as text, which destroys it) cannot be processed by anyone. Review AI suggestions: nothing enters your register without human confirmation by design, and your team remains responsible for the register’s contents. Keep access current: remove departed staff, revoke review links you no longer want live.
Questions
A commitment you need that isn’t here: support@getplinta.app. We will tell you plainly whether we can make it yet.