SLA & SLO

This document defines the Service Level Agreement (SLA) and Service Level Objectives (SLOs) for the platform. SLAs are contractually committed in your subscription. SLOs are internal performance targets we publish for transparency — they tell you what to expect day to day, even where we are not contractually committing.

SLA and SLO reference — contractual commitments for availability, API response, scan completion, and incident notification alongside internal SLO targets
SLA and SLO reference — contractual commitments for availability, API response, scan completion, and incident notification alongside internal SLO targets
The key distinction: an SLA is a contractual commitment with credit consequences if breached (99.9% uptime, 1-hour critical-incident response). An SLO is a published target without contractual penalty (typical scan completion time, P95 API latency).

Platform uptime SLA

The uptime SLA depends on your subscription plan. Higher-tier plans get tighter commitments and bigger credits if breached.

PlanMonthly uptime SLAMax downtime per monthCredit if breached
Starter99.5%3h 36m10% of monthly fee
Growth99.9%43 min25% of monthly fee
Enterprise99.95%21 min50% of monthly fee
Enterprise+ (negotiated)Up to 99.99%Down to 4 minUp to 100% of monthly fee

How uptime is measured: synthetic monitors run every 60 seconds from three geographic regions, probing the portal, the API, and the scan trigger endpoint. An outage is declared when 2 of 3 probes fail for 3 consecutive minutes. The 2-of-3 rule prevents a single regional network blip from triggering a false outage.

Excluded from the SLA:

  • Scheduled maintenance within the published window (4 hours or less per month, with 48-hour notice)
  • Force majeure events (natural disaster, war, government action)
  • Customer-caused issues (your IAM role broken on the cloud side, your network blocking us)
  • Third-party provider outages beyond our control (cloud provider regional outages, your IdP unreachable)

Credit claims must be submitted within 30 days of the incident to support@onam.io with the incident date and impact description. Credits apply to the next billing cycle.

Scan performance SLOs

Scan duration depends primarily on the number of resources in your cloud account, and secondarily on the number of regions you have enabled. The targets below are published SLOs, not contractual SLAs, unless specified in your enterprise agreement.

Account size (resources)Target scan durationP99Notes
Under 1,00015 minutes20 minSingle-region accounts
1,000–10,00060 minutes90 minStandard multi-region
10,000–50,0002 hours3 hoursLarge accounts with many regions
50,000–100,0003 hours4 hoursEnterprise-scale
Over 100,0004 hours6 hoursRequires Enterprise plan

What counts as "scan complete": all engines (Discovery & Inventory, Check, the domain engines, Attack Path, and Risk) have finished processing and findings are visible in the console.

Findings-to-console latency: under 5 minutes from each engine's completion to findings visible in the UI (P99 under 10 minutes). You don't wait for the full scan — findings stream in as each engine completes.

API performance SLOs

The API is sized to support continuous integration into your existing tooling (SIEM, GRC, dashboards). Latency targets vary by endpoint complexity.

Endpoint typeP50P95P99Notes
Gateway health (/gateway/health)Under 50 msUnder 100 msUnder 200 msNo database query
Single resource lookupUnder 200 msUnder 500 msUnder 1 sIndexed query
Findings list (paginated, 50 rows)Under 500 msUnder 1 sUnder 2 sTenant-scoped
Compliance posture scoreUnder 800 msUnder 2 sUnder 3 sAggregate query
Dashboard views (BFF aggregation)Under 1 sUnder 2 sUnder 3 sMulti-domain aggregation
Attack graph traversalUnder 1.5 sUnder 3 sUnder 5 sGraph database query
Compliance report (full export)Under 5 sUnder 10 sUnder 30 sLarge data export

Rate limits apply per plan (see the API Reference). Rate-limit headers (X-RateLimit-Remaining, X-RateLimit-Reset) are returned on every response so your client can self-throttle.

Support response SLAs

Support response is governed by severity classification. Severity is set when you submit a ticket; we may upgrade or downgrade it based on observed impact, with notification to you.

Support response SLA — ticket flow and severity targets for Critical, High, Medium, and Low
Support response SLA — ticket flow and severity targets for Critical, High, Medium, and Low
SeverityDefinitionFirst responseTarget resolutionCoverage
CriticalPlatform inaccessible · data loss risk · security breachUnder 1 hourUnder 4 hours24/7/365
HighCore feature broken with no workaround · scan failuresUnder 4 hoursUnder 24 hoursBusiness hours
MediumFeature degraded · workaround availableUnder 24 hoursUnder 5 business daysBusiness hours
LowQuestions · documentation requests · feature suggestionsUnder 72 hoursUnder 14 business daysBusiness hours

Business hours: Monday–Friday, 09:00–18:00 in your account's primary support region (default IST, configurable for Enterprise).

Critical and High coverage is 24/7/365 for Growth and Enterprise plans.

Support channels: email at support@onam.io · in-app chat (Growth and Enterprise) · dedicated Slack Connect channel (Enterprise).

Scheduled maintenance

The platform schedules maintenance windows during low-traffic hours. Maintenance does not count against the uptime SLA provided proper notice is given.

WindowScheduleMax durationNotice
WeeklySunday 02:00–04:00 UTC2 hours24 hours via status page
MonthlyLast Sunday of month, 02:00–06:00 UTC4 hours72 hours via email and status page
EmergencyAs required (security-critical patches)VariesAs soon as possible — email and status page

The weekly window is applied if needed and skipped if not — most weeks pass without maintenance. The monthly window is reserved for larger updates (schema migrations, dependency upgrades).

Subscribe to maintenance and incident notifications at status.onam.io — the status page also carries real-time platform status and incident history, with email or SMS alerts available.

SLO measurement and reporting

We measure uptime and latency continuously via synthetic monitoring and report results to you monthly. The same metrics drive on-call paging, incident declaration, and post-incident reviews.

SLO measurement and reporting flow — synthetic probes, metrics, alerting, status page, post-incident review
SLO measurement and reporting flow — synthetic probes, metrics, alerting, status page, post-incident review

The five-stage measurement pipeline:

  1. Probe — synthetic monitors run every 60 seconds from 3 geographic regions, hitting the portal, the API, and the scan trigger endpoint.
  2. Collect — latency, success rate, and scan completion times are stored for 13 months as SLA evidence.
  3. Evaluate — SLO breach detection (2-of-3 probes failing for 3 minutes) pages on-call automatically.
  4. Publish — a real-time status page for transparency, plus a monthly SLO report delivered in your account dashboard.
  5. Review — a post-incident review is published within 5 days of any major incident, including root cause and prevention measures.

Monthly SLO report

Available in your account under Settings → SLO Report. It includes:

  • Uptime percentage for the month
  • Scan success rate (scans that completed without error)
  • P95 / P99 API response times
  • Incident count and total downtime minutes
  • SLA credit eligibility
  • A downloadable PDF for compliance evidence

Enterprise SLA addendum

Enterprise plans can negotiate custom SLA terms. Common customizations:

Customizable termDefaultEnterprise range
Uptime SLA99.95%Up to 99.99%
Credit percentage50%Up to 100%
Support response (Critical)Under 1 hourUnder 15 minutes
Dedicated support engineerNoYes
Custom maintenance windowNoYes
Data residencyAccount defaultEU-only · US-only · Government cloud
Scan frequencyDailyUp to hourly
SLA reportingMonthly in-appMonthly plus quarterly review call

Contact sales@onam.io to discuss Enterprise SLA terms.

SLAs are subject to the Master Service Agreement (MSA). In case of conflict, the MSA governs. For SLA credit claims: support@onam.io. Effective 2026-01-01, last reviewed 2026-05-09.

Next steps

  • Trust Center — certifications, incident response, and business continuity targets
  • Data Retention — retention windows and deletion guarantees
  • API Reference — rate limits and the endpoints these SLOs cover
  • Book a demo — discuss Enterprise SLA terms with our team