Service levels — DRAFT

CYN-NEX-SLA-01 Rev A

This is a draft prepared for review. It is not issued, not entered in the document register and not a commitment to any customer. Fields marked [OPERATOR TO SET] are empty by design; every other figure carries its source.

source: docs/specs/CYN-NEX-SLA-01-RevA-DRAFT.md

CYN-NEX-SLA-01 Rev A — Service Level Statement (DRAFT)

Status: DRAFT A, 14 September 2026 — prepared from the build seat under ORDER B §6.2. Not issued. Becomes ISSUED only on the operator's declaration and its entry in CYN-COR-DR-00 with its SHA-256. Nothing here is a promise to a customer until then; every figure below is a measurement with its source, and the fields marked [OPERATOR TO SET] are empty by design. Supersedes: nothing — first draft. Governing: CYN-COR-OC-00 Rev A, rule 1 (measure, don't assert), rule 4 (declare the scope), rule 6 (the qualifier travels with the number) and the Voice section. Sources named per line; the live record is src/lib/security-claims.ts (claims cron-outcome-heartbeat, ingest-liveness, offsite-backup), measured 14 Sep 2026 02:05Z.

1 · Availability — measured, not targeted

No 90-day heartbeat record exists. The external heartbeat ping (external_heartbeat_pings, every 6 minutes) begins 15 Aug 2026 01:30Z. Over the 30 days held: 1,759 of 4,324 pings succeeded (40.7%); the last success was 8 Sep 2026 01:24Z, and every ping since fails on the required-job assertion for settlement-quality-hourly (http delivery timing out). A failed ping means a required scheduled job did not report an outcome; it is not a measurement of the site being unreachable, and no site-availability percentage is derived from it. The control register's heartbeat itself last ran 14 Sep 2026 01:46Z (141 controls seen, 39 findings open).

An availability target is therefore not stated in this revision. It may be stated in a later revision once (a) a probe that measures reachability of the public site and the portal exists and (b) 90 days of its record are held. [OPERATOR TO SET: target, once measurable]

2 · Support response

severityacknowledgeupdate cadencesource
Telemetry not arriving[OPERATOR TO SET][OPERATOR TO SET]none — no ticketing record measured
Portal unavailable[OPERATOR TO SET][OPERATOR TO SET]none
Other[OPERATOR TO SET][OPERATOR TO SET]none

Data-subject requests are the one response time already committed elsewhere: acknowledged within 5 business days, answered within 30 calendar days (Data Requests notice; security-claims.ts SECURITY_COPY.requests).

3 · Telemetry arrival

Three ingest producers are declared as expected to produce (two site telemetry bridges, continuous; one platform weather fetch, hourly); one is retired as never a producer. Latest dead-man run 14 Sep 2026 01:48Z: all three active producers declared_kind_rows_landing. Source: ingest_deadman_subjects, watchdog_findings (ingest-outcome-deadman). This is producer liveness, not per-device completeness.

4 · Data retention — as measured

recordretentionsource
Raw telemetry (mqtt_telemetry)72-hour window, then deletedsrc/lib/backup/spec.ts header; retention config
Rollups (minute/hour/day)five-year record, append-mostlysrc/lib/backup/spec.ts ("the five-year billing record")
Statements (VS-01)24 h settlement, 183 d correctionsCYN-NEX-VS-01 Rev D

5 · Backup — RPO and RTO

Schedule (RPO basis): nightly full/incremental at 07:15 UTC (offsite-backup-daily), a catch-up every 20 minutes 09–49 past the hour (offsite-backup-catchup, cron 9-49/20 * * * *), and a late-arrival cursor watched by backup-interval-contiguity. Scope: the five-year rollup record, configuration and tenancy — not the 72-hour raw window.

Measured state, 14 Sep 2026: last completed run with a manifest is 10 Sep 2026 (full), started 07:15Z, finished 11 Sep 02:28Z via catch-up (completion_mode = resumed_by_catchup). 11 Sep failed; 12 and 13 Sep still running; the artifact monitor reads run_not_reconciled (01:07Z). The achieved RPO at time of writing is therefore about four days, not one night. Source: offsite_backup_runs, watchdog_findings (offsite-backup-artifact, offsite_backup_lease_progress), receipts N-693, N-724.

RTO: not measured. restoreVerify (offsite-backup.server.ts:2513) exists but has never been run against the live store — export_restore_scratch holds 0 rows and no finding records a run. No restore time is quoted. [OPERATOR TO SET: run restore-verify, then quote its duration here]

6 · Exclusions

  • Customer-side networks, gateways, Node-RED bridges and the broker session between site and Cyntech (a will watches the session, not the poll).
  • Third-party feeds (weather, e-mail delivery, LinkedIn).
  • The 72-hour raw telemetry window (superseded by rollups; not backed up).
  • Any figure a report would refuse to print: no saving, availability percentage or uptime is stated without the measurement behind it.

7 · What would change this document

A reachability probe with 90 days of record (§1); a ticketing record (§2); a completed restore-verify (§5); any change to the schedules or retention values cited. Each is a new revision, this one retained.

Measured status: /status.