Service Level Agreement
This Service Level Agreement describes the availability Vallum commits to for the protected traffic path, how that availability is measured, and the credits available when a commitment is missed. It applies to paid production organizations and forms part of the Terms of Service unless a signed agreement says otherwise.
Covered services
The commitments here cover the Vallum proxy edge — request admission, inspection, and forwarding for domains you have onboarded — and the console APIs used to configure it. Trials, free evaluations, staging or preview environments, beta features, and the public marketing site are not covered. Your own origin remains yours to operate; Vallum is responsible for the path in front of it, not for the application behind it.
Availability commitment
Vallum targets 99.5% monthly availability for the proxy edge, measured per calendar month for each protected domain. Monthly availability is calculated as total minutes in the month, minus excluded minutes and downtime minutes, divided by total minutes in the month, minus excluded minutes.
How downtime is measured
Availability is measured by Vallum's monitoring of the proxy edge. A minute counts as downtime when the edge fails to accept and route valid requests for a covered domain — a connection failure, a timeout, or a 5xx response generated by Vallum. Requests that Vallum deliberately blocks under your configured policy are correct behaviour and never count as downtime, and neither does a request Vallum forwarded that your origin then failed to answer. Where your telemetry disagrees with ours, send it with your credit claim and we will review it in good faith.
Service credits
If monthly availability for a covered domain falls below the commitment, you may claim a credit against the monthly fee for that domain: 10% for availability below 99.5% but at or above 99.0%, 25% below 99.0% but at or above 95.0%, and 50% below 95.0%. Credits are calculated per domain against the affected month, are capped at the fee paid for that month, and are applied to a future invoice rather than refunded in cash.
Claiming a credit
Open a support ticket from the console within thirty days of the end of the affected month, with the domain, the dates and times of the incident, and any request identifiers or logs you have. Vallum will respond to a claim within ten business days. Service credits are the sole and exclusive remedy for any failure to meet the availability commitment, and an account must be current on payment for a claim to be honoured. Nothing here expands the limitation of liability in the Terms of Service, which continues to govern any other claim relating to the service.
Support response targets
Support runs on the ticket urgency you select when opening a request. Vallum targets a first human response within one business hour for ASAP tickets, four business hours for urgent tickets, one business day for normal tickets, and two business days for non-urgent tickets, during business hours in the United States Eastern time zone. ASAP is reserved for production traffic that is down or degraded and is answered first; outside business hours it is answered on a best-effort basis. These are response targets, not resolution times.
Scheduled maintenance
Planned maintenance that is expected to interrupt traffic is announced at least two business days in advance and scheduled outside peak hours where practical. Minutes inside an announced window are excluded from availability. Emergency maintenance to address an active security issue may be performed with as much notice as circumstances allow, and Vallum will describe what happened afterwards.
Exclusions
Excluded minutes are those caused by: your origin, DNS, certificates, network, or application being unavailable or misconfigured; changes you or your authorized users make to routing or policy, including rules that block your own traffic; suspension for non-payment or for use prohibited by the Terms of Service; announced maintenance windows; traffic that exceeds a contracted rate or plan limit; and events outside Vallum's reasonable control, such as internet backbone failures, denial-of-service volumes beyond the contracted capacity, or acts of government. A failure at one of Vallum's infrastructure providers is not excluded — that is Vallum's responsibility to you.
Infrastructure dependencies
Vallum runs on third-party infrastructure. The current list of providers in the traffic path, what each one supplies, and where each publishes its own status is maintained on the Service providers page and is updated before a new provider carries production traffic.
Incident communication
During an incident affecting the proxy edge, Vallum notifies the technical contact for each affected organization with what is known, what is affected, and what is being done, and keeps that thread updated until the incident is resolved. A written summary with the cause and the corrective actions is available on request for any incident that consumed availability under this agreement.
Changes to this agreement
Vallum may update this agreement as the service evolves. Changes that materially reduce the commitments take effect at the start of your next renewal term, and the effective date above is revised whenever the text changes. Customers with a signed agreement are governed by the service levels in that agreement where the two conflict.