CYN-NEX-SLA-01 Rev A
This is a draft prepared for review. It is not issued, not entered in the document register and not a commitment to any customer. Fields marked [OPERATOR TO SET] are empty by design; every other figure carries its source.
source: docs/specs/CYN-NEX-SLA-01-RevA-DRAFT.md
CYN-NEX-SLA-01 Rev A — Service Level Statement (DRAFT)
Status: DRAFT A, 14 September 2026 — prepared from the build seat under
ORDER B §6.2. Not issued. Becomes ISSUED only on the operator's declaration
and its entry in CYN-COR-DR-00 with its SHA-256. Nothing here is a promise to
a customer until then; every figure below is a measurement with its source,
and the fields marked [OPERATOR TO SET] are empty by design.
Supersedes: nothing — first draft.
Governing: CYN-COR-OC-00 Rev A, rule 1 (measure, don't assert), rule 4
(declare the scope), rule 6 (the qualifier travels with the number) and the
Voice section. Sources named per line; the live record is
src/lib/security-claims.ts (claims cron-outcome-heartbeat,
ingest-liveness, offsite-backup), measured 14 Sep 2026 02:05Z.
1 · Availability — measured, not targeted
No 90-day heartbeat record exists. The external heartbeat ping
(external_heartbeat_pings, every 6 minutes) begins 15 Aug 2026 01:30Z.
Over the 30 days held: 1,759 of 4,324 pings succeeded (40.7%); the last
success was 8 Sep 2026 01:24Z, and every ping since fails on the required-job
assertion for settlement-quality-hourly (http delivery timing out). A failed
ping means a required scheduled job did not report an outcome; it is not a
measurement of the site being unreachable, and no site-availability
percentage is derived from it. The control register's heartbeat itself last
ran 14 Sep 2026 01:46Z (141 controls seen, 39 findings open).
An availability target is therefore not stated in this revision. It may be stated in a later revision once (a) a probe that measures reachability of the public site and the portal exists and (b) 90 days of its record are held. [OPERATOR TO SET: target, once measurable]
2 · Support response
| severity | acknowledge | update cadence | source |
|---|---|---|---|
| Telemetry not arriving | [OPERATOR TO SET] | [OPERATOR TO SET] | none — no ticketing record measured |
| Portal unavailable | [OPERATOR TO SET] | [OPERATOR TO SET] | none |
| Other | [OPERATOR TO SET] | [OPERATOR TO SET] | none |
Data-subject requests are the one response time already committed
elsewhere: acknowledged within 5 business days, answered within 30 calendar
days (Data Requests notice; security-claims.ts SECURITY_COPY.requests).
3 · Telemetry arrival
Three ingest producers are declared as expected to produce (two site
telemetry bridges, continuous; one platform weather fetch, hourly); one is
retired as never a producer. Latest dead-man run 14 Sep 2026 01:48Z: all three
active producers declared_kind_rows_landing. Source:
ingest_deadman_subjects, watchdog_findings (ingest-outcome-deadman).
This is producer liveness, not per-device completeness.
4 · Data retention — as measured
| record | retention | source |
|---|---|---|
Raw telemetry (mqtt_telemetry) | 72-hour window, then deleted | src/lib/backup/spec.ts header; retention config |
| Rollups (minute/hour/day) | five-year record, append-mostly | src/lib/backup/spec.ts ("the five-year billing record") |
| Statements (VS-01) | 24 h settlement, 183 d corrections | CYN-NEX-VS-01 Rev D |
5 · Backup — RPO and RTO
Schedule (RPO basis): nightly full/incremental at 07:15 UTC
(offsite-backup-daily), a catch-up every 20 minutes 09–49 past the hour
(offsite-backup-catchup, cron 9-49/20 * * * *), and a late-arrival cursor
watched by backup-interval-contiguity. Scope: the five-year rollup record,
configuration and tenancy — not the 72-hour raw window.
Measured state, 14 Sep 2026: last completed run with a manifest is
10 Sep 2026 (full), started 07:15Z, finished 11 Sep 02:28Z via catch-up
(completion_mode = resumed_by_catchup). 11 Sep failed; 12 and 13 Sep still
running; the artifact monitor reads run_not_reconciled (01:07Z). The
achieved RPO at time of writing is therefore about four days, not one night.
Source: offsite_backup_runs, watchdog_findings (offsite-backup-artifact,
offsite_backup_lease_progress), receipts N-693, N-724.
RTO: not measured. restoreVerify (offsite-backup.server.ts:2513)
exists but has never been run against the live store — export_restore_scratch
holds 0 rows and no finding records a run. No restore time is quoted.
[OPERATOR TO SET: run restore-verify, then quote its duration here]
6 · Exclusions
- Customer-side networks, gateways, Node-RED bridges and the broker session between site and Cyntech (a will watches the session, not the poll).
- Third-party feeds (weather, e-mail delivery, LinkedIn).
- The 72-hour raw telemetry window (superseded by rollups; not backed up).
- Any figure a report would refuse to print: no saving, availability percentage or uptime is stated without the measurement behind it.
7 · What would change this document
A reachability probe with 90 days of record (§1); a ticketing record (§2); a completed restore-verify (§5); any change to the schedules or retention values cited. Each is a new revision, this one retained.
Measured status: /status.
