Pre-production policy

Service validation targets

SOCRoot does not currently publish a contractual uptime or response-time SLA. This page records the evidence gates that must be satisfied before a service commitment can be represented as proven.

Why the old guarantee language was removed

A 99.9% uptime claim, fixed response windows, or 24/7 coverage requires deployed monitoring, measured history, staffing, escalation ownership, and contractual terms. Architecture and prototype code alone do not prove those conditions.

Availability

No public uptime guarantee

Required evidence: Measured production deployment, external monitoring, incident records, maintenance process, and recovery tests.

Response time

Agreed per authorized scope

Required evidence: Staffing coverage, paging tests, severity definitions, escalation ownership, and a sustained measurement period.

Remediation

Dry-run and human approval

Required evidence: Integration tests, policy enforcement, rollback validation, audit logs, and client-specific authorization.

Reporting

Deliverables defined before work

Required evidence: Scope, evidence requirements, review criteria, data-retention rules, and acceptance sign-off.

Common language

Severity classification

Critical

Active exploitation or material impact requiring immediate human assessment.

High

A validated weakness with serious impact or a credible path to exploitation.

Medium

A confirmed weakness with constrained impact, prerequisites, or mitigating controls.

Low / informational

A hardening opportunity, observation, or defense-in-depth recommendation.

Classification does not create a response-time guarantee. A response window is defined only in a written engagement with verified coverage.

Need a scoped service target?

Start by defining the environment, severity model, coverage hours, evidence, escalation ownership, and rollback responsibilities.