# AEGIS CYBER Service Level Agreement Framework

**Document Classification:** COMMERCIAL-CONFIDENTIAL  
**Version:** 1.0  
**Effective Date:** January 2026  
**Contract Reference:** AEGIS-SLA-2026-001

---

## Executive Summary

This Service Level Agreement (SLA) Framework defines AEGIS CYBER's commitment to delivering enterprise-grade cybersecurity services with **99.99% availability** to financial institutions across Africa. This framework establishes measurable service targets, credit structures, and escalation procedures that align with Tier-1 banking requirements and regulatory expectations.

---

## 1. Service Availability Commitment

### 1.1 Uptime Guarantee

| Service Tier | Availability Target | Maximum Downtime (Monthly) | Maximum Downtime (Annual) |
|--------------|---------------------|---------------------------|--------------------------|
| **Platinum** | 99.99% | 4 minutes 23 seconds | 52 minutes 34 seconds |
| **Gold** | 99.95% | 21 minutes 55 seconds | 4 hours 23 minutes |
| **Silver** | 99.9% | 43 minutes 50 seconds | 8 hours 46 minutes |

### 1.2 Measurement Period

- **Calculation Window:** Calendar month (00:00:00 UTC Day 1 to 23:59:59 UTC Last Day)
- **Measurement Method:** Synthetic monitoring from 6 regional points (Kampala, Nairobi, Kigali, Lagos, Johannesburg, Cairo)
- **Exclusions:** Scheduled maintenance windows (max 4 hours/month with 72-hour notice)

### 1.3 Availability Formula

```
Monthly Availability % = ((Total Minutes - Downtime Minutes) / Total Minutes) × 100
```

---

## 2. Performance SLAs

### 2.1 Threat Detection & Response

| Metric | Platinum SLA | Gold SLA | Silver SLA |
|--------|-------------|----------|------------|
| **Threat Detection Latency** | < 150ms | < 200ms | < 500ms |
| **Alert Generation** | < 1 second | < 3 seconds | < 10 seconds |
| **Automated Response Initiation** | < 5 seconds | < 15 seconds | < 60 seconds |
| **Bio-Vault Behavioral Analysis** | < 100ms | < 200ms | < 500ms |
| **KYT Transaction Scoring** | < 50ms | < 100ms | < 250ms |

### 2.2 API Response Times

| Endpoint Category | P50 Target | P95 Target | P99 Target |
|-------------------|-----------|-----------|-----------|
| Authentication APIs | 100ms | 250ms | 500ms |
| Threat Intelligence | 150ms | 300ms | 600ms |
| Compliance Reporting | 500ms | 1.5s | 3s |
| Dashboard Queries | 200ms | 500ms | 1s |
| Webhook Delivery | 1s | 3s | 5s |

### 2.3 Data Durability

| Metric | Commitment |
|--------|------------|
| **Audit Log Retention** | 99.999999999% (11 nines) |
| **Threat Event Durability** | 99.9999999% (9 nines) |
| **Configuration Backup** | 99.99% with 15-minute RPO |
| **Ghost Core Shadow Ledger** | 99.999% with real-time sync |

---

## 3. Regional Availability

### 3.1 East African Deployment

| Region | Primary DC | Failover DC | Target Latency |
|--------|-----------|-------------|----------------|
| **Uganda** | Kampala (DC-KLA-001) | Jinja (DC-JIN-001) | < 10ms |
| **Kenya** | Nairobi (DC-NBO-001) | Mombasa (DC-MBA-001) | < 15ms |
| **Rwanda** | Kigali (DC-KGL-001) | Bugesera (DC-BGS-001) | < 12ms |
| **Tanzania** | Dar es Salaam (DC-DAR-001) | Arusha (DC-ARU-001) | < 18ms |

### 3.2 Gulu Mesh Network Guarantees

| Scenario | Availability Target | Recovery Time |
|----------|---------------------|---------------|
| Single Node Failure | 100% (automatic failover) | < 30 seconds |
| Regional Fiber Cut | 99.9% (satellite backhaul) | < 5 minutes |
| Multiple Node Failure | 99.5% (mesh rerouting) | < 2 minutes |
| Full Regional Blackout | Offline mode + 12hr sync | Upon restoration |

### 3.3 Sovereign Edge Guarantees

- **Data Sovereignty:** 100% of customer data remains within designated sovereign boundaries
- **Cross-Border Latency:** < 50ms for authorized inter-regional queries
- **Offline Transaction Processing:** Up to 10,000 transactions/node during connectivity loss
- **Delta-Sync Recovery:** < 30 minutes post-restoration for full consistency

---

## 4. Support Response Times

### 4.1 Incident Severity Classification

| Severity | Definition | Examples |
|----------|------------|----------|
| **P1 - Critical** | Complete service outage or active security breach | System down, data exfiltration detected |
| **P2 - High** | Major feature degradation affecting operations | Threat detection delayed, compliance reporting failed |
| **P3 - Medium** | Partial service impact with workaround available | Dashboard slow, single node offline |
| **P4 - Low** | Minor issues or enhancement requests | UI cosmetic issues, documentation updates |

### 4.2 Response Time Commitments

| Severity | Platinum | Gold | Silver |
|----------|----------|------|--------|
| **P1 - Critical** | 15 minutes | 30 minutes | 1 hour |
| **P2 - High** | 1 hour | 2 hours | 4 hours |
| **P3 - Medium** | 4 hours | 8 hours | 24 hours |
| **P4 - Low** | 24 hours | 48 hours | 72 hours |

### 4.3 Resolution Time Targets

| Severity | Target Resolution | Maximum Resolution |
|----------|-------------------|-------------------|
| **P1 - Critical** | 1 hour | 4 hours |
| **P2 - High** | 4 hours | 12 hours |
| **P3 - Medium** | 24 hours | 72 hours |
| **P4 - Low** | 5 business days | 10 business days |

---

## 5. Service Credits

### 5.1 Availability Credit Structure

| Monthly Availability | Service Credit (% of Monthly Fee) |
|---------------------|----------------------------------|
| 99.99% - 99.95% | 0% (Within SLA) |
| 99.94% - 99.90% | 10% |
| 99.89% - 99.50% | 25% |
| 99.49% - 99.00% | 50% |
| Below 99.00% | 100% |

### 5.2 Performance Credit Structure

| SLA Breach Type | Credit Per Occurrence |
|-----------------|----------------------|
| Threat detection > 2x target | 5% |
| API P99 > 2x target | 3% |
| Support response missed | 5% per incident |
| Data sovereignty violation | 100% + contract review |

### 5.3 Credit Caps and Conditions

- **Maximum Monthly Credit:** 100% of monthly service fee
- **Credit Request Window:** Within 30 days of incident
- **Verification Required:** Customer must provide incident timestamp and impact description
- **Exclusions:** Customer-caused issues, force majeure, scheduled maintenance

### 5.4 Credit Application Process

1. Customer submits credit request via support portal
2. AEGIS validates against monitoring data within 5 business days
3. Approved credits applied to next billing cycle
4. Disputed credits escalated to account executive

---

## 6. Maintenance Windows

### 6.1 Scheduled Maintenance

| Maintenance Type | Notice Period | Maximum Duration | Frequency |
|------------------|---------------|-----------------|-----------|
| **Routine Updates** | 72 hours | 30 minutes | Weekly |
| **Security Patches** | 24 hours | 1 hour | As needed |
| **Major Upgrades** | 7 days | 4 hours | Quarterly |
| **Infrastructure** | 14 days | 6 hours | Bi-annually |

### 6.2 Maintenance Windows

- **Primary Window:** Sunday 02:00-06:00 EAT (East Africa Time)
- **Secondary Window:** Wednesday 02:00-04:00 EAT
- **Emergency Patches:** Any time with maximum 4-hour notice

### 6.3 Zero-Downtime Commitment

AEGIS employs rolling deployment and hot-standby architecture to minimize service interruption:

- Blue-green deployments for application updates
- Live database migrations with shadow writes
- Canary releases with automatic rollback
- Ghost Core maintains continuity during CBS maintenance

---

## 7. Disaster Recovery & Business Continuity

### 7.1 Recovery Objectives

| Metric | Platinum | Gold | Silver |
|--------|----------|------|--------|
| **RTO (Recovery Time Objective)** | 15 minutes | 1 hour | 4 hours |
| **RPO (Recovery Point Objective)** | 0 (synchronous) | 5 minutes | 15 minutes |
| **Failover Automation** | Fully automatic | Semi-automatic | Manual |

### 7.2 Disaster Scenarios

| Scenario | Recovery Strategy | Target Recovery |
|----------|-------------------|-----------------|
| Single DC Failure | Automatic failover to secondary | < 30 seconds |
| Regional Outage | Cross-region failover | < 5 minutes |
| Ransomware Attack | Air-gapped vault restoration | < 4 hours |
| Catastrophic Data Loss | Immutable backup restoration | < 8 hours |

### 7.3 Testing & Validation

- **Quarterly:** Tabletop exercises with customer participation
- **Semi-annually:** Full failover drill with documented results
- **Annually:** Third-party audit of DR capabilities
- **Monthly:** Automated backup verification and integrity checks

---

## 8. Security SLAs

### 8.1 Vulnerability Management

| Severity | Patch Timeline | Verification |
|----------|---------------|--------------|
| **Critical (CVSS 9.0+)** | 24 hours | Immediate scan |
| **High (CVSS 7.0-8.9)** | 72 hours | 24-hour scan |
| **Medium (CVSS 4.0-6.9)** | 7 days | Weekly scan |
| **Low (CVSS 0.1-3.9)** | 30 days | Monthly scan |

### 8.2 Compliance Commitments

| Standard | Commitment | Audit Frequency |
|----------|------------|-----------------|
| **SOC 2 Type II** | Maintain certification | Annual |
| **ISO 27001** | Maintain certification | Annual |
| **PCI DSS** | Level 1 compliance | Quarterly |
| **PDPO 2019 (Uganda)** | Full compliance | Continuous |
| **Kenya DPA 2019** | Full compliance | Continuous |

### 8.3 Incident Notification

| Incident Type | Customer Notification | Regulator Notification |
|---------------|----------------------|------------------------|
| Data Breach (confirmed) | 1 hour | Per regulation (72 hours max) |
| Security Incident (contained) | 4 hours | If required |
| Attempted Breach (blocked) | 24 hours | N/A |

---

## 9. Reporting & Transparency

### 9.1 Standard Reports

| Report | Frequency | Delivery |
|--------|-----------|----------|
| **Availability Report** | Monthly | Dashboard + Email |
| **Performance Metrics** | Weekly | Dashboard |
| **Security Summary** | Monthly | Secure portal |
| **Compliance Status** | Quarterly | Executive briefing |
| **SLA Scorecard** | Monthly | Account review |

### 9.2 Real-Time Monitoring

Customers have 24/7 access to:
- Live availability dashboard
- Performance metrics with historical trends
- Active incident status and updates
- Threat intelligence feed status
- Regional node health

### 9.3 Executive Reviews

| Tier | Review Frequency | Attendees |
|------|------------------|-----------|
| **Platinum** | Monthly | VP-level |
| **Gold** | Quarterly | Director-level |
| **Silver** | Semi-annually | Manager-level |

---

## 10. Escalation Matrix

### 10.1 Technical Escalation

| Level | Timeframe | Contact | Authority |
|-------|-----------|---------|-----------|
| **L1** | 0-15 min | SOC Analyst | Initial triage |
| **L2** | 15-60 min | Senior Engineer | Advanced troubleshooting |
| **L3** | 1-4 hours | Platform Architect | Architecture decisions |
| **L4** | 4+ hours | CTO | Emergency measures |

### 10.2 Business Escalation

| Level | Trigger | Contact |
|-------|---------|---------|
| **1** | SLA at risk | Account Manager |
| **2** | SLA breached | Regional Director |
| **3** | Major incident | VP Customer Success |
| **4** | Contract jeopardy | CEO |

### 10.3 Emergency Contacts

| Role | Availability | Response Time |
|------|--------------|---------------|
| **24/7 SOC** | Always | Immediate |
| **On-Call Engineer** | Always | 15 minutes |
| **Incident Commander** | Always | 30 minutes |
| **Executive Sponsor** | Business hours | 2 hours |

---

## 11. Contract Terms

### 11.1 SLA Effective Period

- **Start Date:** Upon production deployment sign-off
- **Duration:** Aligned with master service agreement
- **Review Cycle:** Annual review with adjustment opportunity

### 11.2 SLA Modifications

- 90-day notice required for material changes
- Customer approval required for SLA reductions
- Improvements effective immediately upon notice

### 11.3 Termination Rights

Customer may terminate without penalty if:
- Availability falls below 99.5% for 3 consecutive months
- P1 resolution exceeds 24 hours
- Data sovereignty violation occurs
- Security breach due to AEGIS negligence

---

## 12. Definitions

| Term | Definition |
|------|------------|
| **Availability** | Time service is operational and accessible |
| **Downtime** | Service unavailable for more than 5 consecutive minutes |
| **Scheduled Maintenance** | Pre-announced maintenance within designated windows |
| **Emergency Maintenance** | Unplanned maintenance to address security or stability |
| **Incident** | Any event causing service degradation or outage |
| **Business Day** | Monday-Friday, 08:00-18:00 EAT, excluding public holidays |

---

## Document Approval

| Role | Name | Signature | Date |
|------|------|-----------|------|
| **Chief Executive Officer** | _________________ | _________________ | _______ |
| **Chief Technology Officer** | _________________ | _________________ | _______ |
| **VP Customer Success** | _________________ | _________________ | _______ |
| **Customer Representative** | _________________ | _________________ | _______ |

---

## Appendix A: SLA Calculation Examples

### Example 1: Monthly Availability Calculation

```
Total minutes in month: 43,200 (30 days)
Downtime incidents:
  - Incident 1: 3 minutes
  - Incident 2: 1 minute
Total downtime: 4 minutes

Availability = (43,200 - 4) / 43,200 × 100 = 99.99%
Result: Within Platinum SLA
```

### Example 2: Service Credit Calculation

```
Monthly fee: $10,000
Availability achieved: 99.85%
Credit tier: 25%

Credit amount = $10,000 × 25% = $2,500
Applied to next invoice
```

---

## Appendix B: Regional Compliance Mapping

| Region | Data Residency | Regulatory Body | Notification Timeline |
|--------|---------------|-----------------|----------------------|
| Uganda | Mandatory | PDPA/NITA-U | 72 hours |
| Kenya | Mandatory | ODPC | 72 hours |
| Rwanda | Recommended | RURA | 48 hours |
| Nigeria | Mandatory | NITDA | 72 hours |

---

*This SLA Framework represents AEGIS CYBER's commitment to operational excellence and customer success in securing African financial infrastructure.*

**Document Control:**
- Version 1.0 | January 2026
- Classification: Commercial-Confidential
- Distribution: Authorized personnel only
