Availability
No public uptime guarantee
Required evidence: Measured production deployment, external monitoring, incident records, maintenance process, and recovery tests.
Pre-production policy
SOCRoot does not currently publish a contractual uptime or response-time SLA. This page records the evidence gates that must be satisfied before a service commitment can be represented as proven.
A 99.9% uptime claim, fixed response windows, or 24/7 coverage requires deployed monitoring, measured history, staffing, escalation ownership, and contractual terms. Architecture and prototype code alone do not prove those conditions.
Availability
Required evidence: Measured production deployment, external monitoring, incident records, maintenance process, and recovery tests.
Response time
Required evidence: Staffing coverage, paging tests, severity definitions, escalation ownership, and a sustained measurement period.
Remediation
Required evidence: Integration tests, policy enforcement, rollback validation, audit logs, and client-specific authorization.
Reporting
Required evidence: Scope, evidence requirements, review criteria, data-retention rules, and acceptance sign-off.
Common language
Active exploitation or material impact requiring immediate human assessment.
A validated weakness with serious impact or a credible path to exploitation.
A confirmed weakness with constrained impact, prerequisites, or mitigating controls.
A hardening opportunity, observation, or defense-in-depth recommendation.
Classification does not create a response-time guarantee. A response window is defined only in a written engagement with verified coverage.
Start by defining the environment, severity model, coverage hours, evidence, escalation ownership, and rollback responsibilities.