CorporateStack Standard Service Level Agreement (SLA)

Version: 2026/V2.0
Effective Date: 01/01/2026
Last Updated: 31/12/2026

1. Introduction

This Service Level Agreement (“SLA”) defines the service commitments provided by CorporateStack for its Software-as-a-Service (SaaS) platform, including service availability, technical support, incident management, operational response, and service performance objectives.

The purpose of this SLA is to establish clear operational expectations between CorporateStack and its customers while supporting the reliable delivery of enterprise cloud services.

This SLA applies to CorporateStack cloud-hosted production environments and forms part of CorporateStack’s enterprise governance framework.

Unless otherwise agreed in writing, this SLA applies to all active subscription services delivered under the applicable Sales Order.

This SLA should be read together with the following CorporateStack documents:

  • CorporateStack Enterprise End User License Agreement (EULA)
  • CorporateStack Data Processing Addendum (DPA)
  • CorporateStack Privacy Statement
  • CorporateStack Security & Compliance Overview
  • CorporateStack Business Continuity & Disaster Recovery Overview

In the event of any conflict between this SLA and an executed Sales Order, the Sales Order shall prevail solely with respect to the commercial terms expressly stated therein.

2. Scope 

This Service Level Agreement (SLA) applies to CorporateStack’s production Software-as-a-Service (SaaS) environment and defines the operational service commitments provided throughout the active subscription term.

Unless otherwise agreed in writing, this SLA applies exclusively to CorporateStack cloud-hosted production environments delivered under an active Sales Order.

2.1 Supported Services

This SLA applies to the CorporateStack solutions licensed by the Customer under the applicable Sales Order, including, but not limited to:

  • Enterprise Resource Planning (ERP)
  • Human Resources Management System (HRMS)
  • Customer Relationship Management (CRM)
  • Supply Chain & Procurement
  • Inventory & Warehouse Management
  • Fixed Asset Management
  • Project Management
  • Manufacturing & Production Management
  • CorporateStack Industry Solutions
  • Customer & Supplier Portals
  • CorporateStack Integration Services
  • Other CorporateStack cloud services subscribed to by the Customer.

The service commitments defined in this SLA apply only to the subscribed modules operating within the supported production environment.

2.2 Services Covered

This SLA governs CorporateStack’s operational commitments relating to:

  • Service availability;
  • Technical and functional support;
  • Incident management and service restoration;
  • Service request management;
  • Planned and emergency maintenance;
  • Business Continuity and Disaster Recovery (BCDR);
  • Platform monitoring and operational performance; and
  • Customer communication relating to service availability and operational incidents.
2.4 Environment Coverage

The commitments contained in this SLA apply only to supported production environments.

Unless otherwise agreed in writing, this SLA does not apply to:

  • Development, testing, staging, sandbox, or demonstration environments;
  • Beta, preview, pilot, or evaluation features; or
  • Customer-managed or third-party hosted environments.
2.5 Relationship to Other Agreements

This SLA establishes CorporateStack’s operational service commitments and should be read together with the applicable Sales Order, the CorporateStack Enterprise End User License Agreement (EULA), the Data Processing Addendum (DPA), the Privacy Statement, and other applicable CorporateStack governance documents.

Where a customer-specific agreement contains service commitments that differ from this standard SLA, the executed customer agreement shall prevail solely with respect to those expressly agreed commitments.

3. Service Availability

CorporateStack is committed to delivering secure, reliable, and highly available cloud services through resilient infrastructure, proactive monitoring, and documented operational procedures.

3.1 Service Availability Commitment

CorporateStack targets 99.9% monthly service availability for production environments hosted and managed by CorporateStack under the applicable Sales Order.

Monthly service availability is calculated using the following formula:

Availability (%) = (Total Minutes in the Calendar Month – Unplanned Downtime) ÷ Total Minutes in the Calendar Month × 100

Availability measurements are based on the production environment only.

3.2 Support Hours

CorporateStack provides the following support coverage:

 

ServiceAvailability
Standard Technical & Functional Support7 Days 09:00 – 18:00
Critical Incident Support (Priority 1)24 Hours × 7 Days
Customer Support Portal24 Hours × 7 Days
Support Email24 Hours × 7 Days

Support requests submitted outside Standard Support Hours for non-critical issues will be acknowledged on the next Business Day.

3.3 Planned Maintenance

To maintain platform security, reliability, and performance, CorporateStack may perform scheduled maintenance activities.

Where reasonably practicable:

  • Planned maintenance will be communicated at least 72 hours in advance;
  • Maintenance will be scheduled outside standard business hours whenever possible; and
  • Customers will be notified through the appropriate communication channels.

Planned maintenance windows are excluded from the monthly availability calculation.

 

3.4 Emergency Maintenance

CorporateStack may perform emergency maintenance without prior notice where reasonably necessary to:

  • Protect the security of the Services;
  • Prevent service degradation;
  • Address critical vulnerabilities;
  • Restore service availability; or
  • Protect Customer Data.

Where practical, customers will be notified as soon as reasonably possible.

3.5 Availability Exclusions

The monthly availability commitment does not apply to service interruptions resulting from:

  • Planned maintenance windows;
  • Emergency maintenance;
  • Force majeure events;
  • Customer-controlled systems, infrastructure, or configurations;
  • Internet service provider or telecommunications failures;
  • Third-party software or services outside CorporateStack’s operational control;
  • Customer misuse, unauthorized modifications, or unsupported configurations; or
  • Suspension of Services in accordance with the applicable agreement.
3.6 Service Monitoring

CorporateStack continuously monitors the availability and operational health of the production platform to support proactive incident detection, rapid response, and ongoing service improvement.

Service availability metrics are reviewed as part of CorporateStack’s operational governance and may be included within customer service performance reports.

4. Support Services

CorporateStack provides technical and functional support services to assist customers in maintaining the availability, stability, and effective operation of the subscribed CorporateStack solutions throughout the active subscription term. Support services are delivered by qualified technical and functional specialists and are provided in accordance with the service commitments defined in this Service Level Agreement.

4.1 Support Channels

Customers may contact CorporateStack through the following official support channels:

  • CorporateStack Customer Support Portal
  • Dedicated Support Email
  • Telephone Hotline (Critical Priority incidents only)
  • Customer Success Manager or Account Manager (where applicable) Support requests submitted through authorized channels are logged, tracked, prioritized, and managed in accordance with CorporateStack’s Incident Management procedures.
4.2 Support Coverage

CorporateStack provides:

  • Technical support for platform availability and operational issues;
  • Functional support relating to standard product functionality;
  • Incident investigation and resolution;
  • Service request management;
  • Assistance with standard product configuration;
  • Guidance relating to product usage and standard platform capabilities.
4.3 Services Not Included

Unless otherwise agreed in writing, the following services are outside the scope of this SLA:

  • Product customization or software development;
  • Business process consulting;
  • Data migration activities;
  • Customer training;
  • Implementation services;
  • Third-party software support;
  • Customer-developed integrations;
  • On-site services; and
  • Change Requests (CRs) or enhancement requests. Such services may be provided under a separate Professional Services Agreement or Statement of Work (SoW).
4.4 Customer Support Obligations

To enable effective support, the Customer shall:

  • Provide sufficient information to reproduce reported issues;
  • Cooperate with CorporateStack during troubleshooting and investigation;
  • Provide timely access to authorized personnel where required;
  • Designate authorized contacts for support communications; and
  • Promptly validate the resolution of reported incidents.
4.5 Continuous Service Improvement

CorporateStack periodically reviews support performance, customer feedback, incident trends, and operational metrics to improve service quality and enhance the overall customer support experience.

4.6 Key Support Services
  • Technical Support
  • Functional Support
  • Incident Resolution
  • Service Request Handling
  • Customer Success Coordination
  • Continuous Service Improvement

5. Incident Management

CorporateStack maintains a structured Incident Management process designed to restore normal service operation as quickly as reasonably practicable while minimizing the impact on the Customer’s business operations. All reported incidents are managed through a standardized operational framework that ensures consistent classification, prioritization, investigation, escalation, resolution, and communication throughout the incident lifecycle.

5.1 Incident Definition

An Incident is an unplanned interruption to, or reduction in the quality, availability, or performance of the subscribed CorporateStack Services. Incidents are classified according to their business impact and operational urgency using the Priority Matrix defined in this SLA.

 

5.2 Incident Lifecycle

All incidents follow the standard CorporateStack incident management process: Where immediate resolution is not possible, CorporateStack may implement a temporary workaround to restore service while a permanent resolution is developed.

5.3 Incident Logging

Incidents may be reported through any of the authorized CorporateStack support channels. Each incident is assigned a unique tracking reference and recorded within CorporateStack’s service management system to enable end-to-end tracking, reporting, and auditability.

5.4 Investigation & Resolution

CorporateStack investigates each incident according to its assigned priority and business impact. Resolution activities may include:

  • Technical investigation;
  • Functional analysis;
  • Configuration correction;
  • Software correction;
  • Infrastructure recovery;
  • Service restoration; or
  • Implementation of an acceptable workaround. Where third-party products or customer-managed systems contribute to the reported issue, CorporateStack will provide reasonable assistance in identifying the root cause; however, resolution of issues outside CorporateStack’s operational control remains the responsibility of the applicable third party or the Customer.
5.5 Escalation

Incidents that cannot be resolved within the applicable service targets, or that require specialized technical expertise, are escalated through CorporateStack’s defined technical and management escalation procedures. Escalation is based on the severity of the incident, customer impact, and operational urgency.

5.6 Customer Communication

CorporateStack provides appropriate progress updates throughout the lifecycle of significant incidents. For Critical (Priority 1) incidents, customers will receive periodic status updates until service has been restored or an agreed workaround has been implemented.

5.7 Incident Closure

An incident is considered resolved when:

  • The reported issue has been corrected;
  • An acceptable workaround has been implemented and agreed with the Customer; or
  • The Customer confirms that the incident has been satisfactorily resolved. Closed incidents remain available within CorporateStack’s service management records for reporting, audit, and service improvement purposes.
5.8 Major Incidents

Incidents that significantly affect the availability of the CorporateStack platform or multiple customers are managed as Major Incidents. Major Incidents receive the highest operational priority and are subject to executive oversight, coordinated response procedures, and enhanced customer communication until normal service is restored.

5.9 Key Incident Management Controls
  • Standardized Incident Lifecycle
  • Priority-Based Classification
  • Controlled Escalation Procedures
  • Major Incident Management
  • Customer Communication
  • Root Cause Investigation
  • Resolution or Workaround Management
  • Incident Reporting & Continuous Improvement Where recurring or systemic issues are identified, CorporateStack may initiate an internal Problem Management process to determine the underlying root cause and implement permanent corrective actions as part of its continuous service improvement program.

6. Service Request Management

CorporateStack provides Service Request Management for standard operational requests that do not result from a system failure or service interruption. Service Requests are managed through a structured process designed to ensure timely fulfillment, appropriate authorization, and consistent service delivery.

6.1 Service Request Definition

A Service Request is a customer-initiated request for a standard operational service, information, or administrative action that does not relate to an Incident. Typical Service Requests include:

  • User account creation, modification, or deactivation;
  • Password resets and access assistance;
  • Role and permission changes;
  • Standard configuration requests;
  • Data restoration requests (where available);
  • Assistance with standard product functionality;
  • General product guidance; and
  • Other operational requests supported by CorporateStack.
6.2 Request Submission

Service Requests may be submitted through CorporateStack’s authorized support channels, including:

  • Customer Support Portal;
  • Dedicated Support Email; or
  • Customer Success Manager or Account Manager, where applicable. Each request is assigned a unique reference number and tracked through CorporateStack’s service management system until completion.
6.3 Request Fulfilment

Service Requests are processed according to their nature, complexity, business impact, and any required approvals. Certain requests may require Customer authorization or additional verification before execution to protect the security and integrity of Customer Data.

6.4 Requests Outside the Scope

The following are not considered standard Service Requests under this SLA:

  • Product enhancements;
  • Software customization;
  • New feature development;
  • Business consulting services;
  • Data migration projects;
  • Integration development;
  • Change Requests (CRs); and
  • Professional Services. Such requests will be evaluated separately and may require a Statement of Work (SoW), Commercial Proposal, or Change Request Agreement.
6.5 Customer Responsibilities

The Customer shall:

  • Submit accurate and complete request information;
  • Obtain any required internal approvals before submitting requests;
  • Cooperate with CorporateStack where additional information or validation is required; and
  • Promptly review and confirm completion of fulfilled requests.
6.6 Key Service Request Controls
  • Standardized Request Management Process
  • Secure Request Validation
  • Request Tracking and Auditability
  • Controlled Administrative Changes
  • Customer Authorization Where Required
  • Operational Service Fulfilment

7. Severity Levels & Service Commitments

CorporateStack classifies Incidents according to their business impact and operational urgency to ensure that support resources are prioritized appropriately and service restoration activities are performed in a consistent and timely manner. The severity assigned to an Incident may be reviewed and adjusted during its lifecycle if additional information changes its business impact or urgency.

7.1 Incident Severity Matrix
PriorityBusiness ImpactInitial Response TargetService Restoration Target
Priority 1 (Critical)Complete loss of the production service or a critical business function. No reasonable workaround is available.Within 15 MinutesWithin 4 Hours or provide an acceptable workaround
Priority 2 (High)Major functionality is significantly impaired, affecting multiple users or critical business operations. A temporary workaround may be available.Within 1 HourWithin 8 Business Hours
Priority 3 (Medium)Non-critical functionality is affected with limited business impact. A reasonable workaround is available.Within 4 Business HoursWithin 2 Business Days
Priority 4 (Low)Cosmetic issues, general inquiries, documentation requests, or minor usability issues with no material business impact.Within 1 Business DayWithin 5 Business Days

7.1.1 Response Targets

The Initial Response Target represents the time within which CorporateStack will acknowledge the Incident, begin investigation, and assign the appropriate support resources.

7.1.2 Service Restoration Targets

The Service Restoration Target represents the target time within which CorporateStack will restore the affected service or provide a commercially reasonable workaround that enables normal business operations to continue. Where a permanent software correction cannot reasonably be delivered within the applicable target, CorporateStack may provide a temporary workaround while the permanent resolution is incorporated into a future software release. Response and restoration targets apply only during the applicable Support Hours, except for Priority 1 (Critical) incidents, which receive 24×7 support coverage.

7.2 Standard Service Request Targets

Service RequestTarget Fulfilment
Password ResetWithin 2 Business Hours
User Account Creation / DeactivationWithin 1 Business Day
Role or Permission ModificationWithin 1 Business Day
Standard Configuration RequestWithin 2 Business Days
Data Export RequestIn accordance with the applicable agreement or DPA
Data Restoration RequestSubject to validation and backup availability
Product Guidance / Functional AssistanceAccording to the applicable Incident Priority
Feature Request / EnhancementLogged for Product Management review (No SLA applies)
7.2.1 Service Commitment Notes

Service targets represent CorporateStack’s operational objectives and are measured during the applicable Support Hours unless otherwise specified. Restoration targets may be satisfied through either a permanent resolution or a commercially reasonable workaround. Service Request fulfillment targets may vary where Customer approvals, third-party dependencies, or additional technical validation are required. Feature requests, product enhancements, and Change Requests (CRs) are managed through CorporateStack’s Product Management and Professional Services processes and are not subject to the response or restoration targets defined in this SLA.

7.2.2 Key Service Commitments

Risk-Based Incident Prioritization Defined Initial Response Targets Defined Service Restoration Targets Priority-Based Resource Allocation Standard Service Request Fulfillment Targets Continuous Service Performance Monitoring

8. Escalation Process

CorporateStack maintains a structured escalation process to ensure that Incidents and Service Requests receive the appropriate level of technical expertise and management attention throughout their lifecycle. Escalation may occur automatically based on service commitments or manually where the complexity, business impact, or operational risk of an issue requires additional resources or executive oversight.

8.1 Functional Escalation

Functional escalation is initiated when an Incident or Service Request requires specialized technical expertise beyond the initially assigned support resource. Incidents may be escalated through successive support levels to ensure timely investigation and resolution.

Support LevelResponsibility
Level 1 (L1)Initial customer support, ticket logging, issue validation, basic troubleshooting, and service request handling.
Level 2 (L2)Advanced functional and technical investigation, configuration analysis, application support, and workaround implementation.
Level 3 (L3)Product engineering, software defect resolution, infrastructure support, and complex technical analysis.
8.2 Management Escalation

Management escalation may be initiated where:

  • A Critical (Priority 1) Incident remains unresolved beyond the applicable Service Restoration Target.
  • An Incident has a significant operational or business impact.
  • Multiple customers are affected by the same issue.
  • Executive coordination or business decisions are required.
  • Customer satisfaction or business continuity may be materially affected. Management escalation ensures appropriate visibility, resource allocation, customer communication, and executive oversight until the Incident has been resolved or service has been restored.
8.3 Customer Communication

For Major Incidents and Priority 1 Incidents, CorporateStack will provide periodic status updates throughout the Incident lifecycle until service has been restored or an agreed workaround has been implemented. Updates may include:

  • Current service status;
  • Investigation progress;
  • Known business impact;
  • Workaround availability;
  • Estimated restoration progress (where reasonably available); and
  • Confirmation upon service restoration.
8.4 Major Incident Coordination

Major Incidents are managed through a coordinated response involving the appropriate technical, operational, and management teams. Following resolution, CorporateStack may conduct an internal post-incident review to identify contributing factors, corrective actions, and opportunities for continuous service improvement.

8.5 Escalation Principles

CorporateStack’s escalation process is designed to:

  • Accelerate issue resolution.
  • Allocate appropriate technical expertise.
  • Maintain effective customer communication.
  • Minimize operational disruption.
  • Support business continuity.
  • Continuously improve service quality.
8.5.1 Key Escalation Controls

Multi-Level Technical Escalation Management Escalation Major Incident Coordination Executive Oversight Customer Status Communications Post-Incident Review Continuous Service Improvement

9. Planned & Emergency Maintenance

CorporateStack performs maintenance activities to ensure the continued security, availability, reliability, and performance of the Services. Maintenance may include software updates, security patches, infrastructure improvements, bug fixes, performance optimization, and other operational activities necessary to support the ongoing delivery of the Services.

9.1 Planned Maintenance

Planned maintenance refers to scheduled activities performed under normal operating conditions. Where reasonably practicable, CorporateStack will:

  • Provide customers with at least seventy-two (72) hours’ prior notice of planned maintenance;
  • Schedule maintenance outside standard business hours whenever reasonably possible; and
  • Take reasonable steps to minimize service disruption. Planned maintenance windows are not considered Service Unavailability and are excluded from the calculation of the monthly Service Availability commitment.
9.2 Emergency Maintenance

CorporateStack may perform emergency maintenance without prior notice where reasonably necessary to:

  • Address critical security vulnerabilities;
  • Protect the confidentiality, integrity, or availability of the Services;
  • Prevent or mitigate significant service degradation;
  • Restore service availability following an operational incident; or
  • Comply with legal, regulatory, or infrastructure provider requirements. Where practicable, CorporateStack will notify affected customers as soon as reasonably possible following the commencement of emergency maintenance.
9.3 Maintenance Activities

Maintenance activities may include, without limitation:

  • Platform software updates;
  • Security patches and vulnerability remediation;
  • Infrastructure maintenance;
  • Database optimization;
  • Performance improvements;
  • Bug fixes;
  • Operating system and middleware updates; and
  • Cloud infrastructure maintenance coordinated with the underlying infrastructure provider.
9.4 Customer Responsibilities During Maintenance

Customers are encouraged to:

  • Avoid performing critical operational activities during notified maintenance windows where reasonably possible;
  • Ensure appropriate users receive maintenance notifications;
  • Report any unexpected issues following maintenance activities through the CorporateStack Support Portal or other authorized support channels.
9.5 Maintenance Notifications

Maintenance notifications may be communicated through one or more of the following channels:

  • CorporateStack Support Portal;
  • Email notifications to authorized customer contacts;
  • Customer Success Manager or Account Manager (where applicable); or
  • Other agreed communication channels.
9.6 Key Maintenance Commitments
  • Planned Maintenance Notifications
  • Emergency Maintenance Procedures
  • Security Patch Deployment
  • Platform Updates and Enhancements
  • Operational Continuity
  • Customer Communication
  • Minimal Service Disruption

10. Business Continuity & Disaster Recovery

CorporateStack maintains a Business Continuity and Disaster Recovery (BCDR) framework designed to support the resilience of its cloud services, protect Customer Data, and restore critical platform services following significant operational disruptions. The BCDR framework combines resilient cloud infrastructure, automated backup processes, geographically separated disaster recovery capabilities, documented recovery procedures, and operational governance to support the continued delivery of the Services. Further information regarding CorporateStack’s business continuity strategy and disaster recovery architecture is available in the CorporateStack Business Continuity & Disaster Recovery (BCDR) Overview.

10.1 Backup & Data Protection

CorporateStack performs automated backups of Customer Data as part of its managed cloud operations. Backup processes are designed to support operational recovery, business continuity, and disaster recovery while protecting the confidentiality, integrity, and availability of Customer Data. Backup data is encrypted, access-controlled, and managed in accordance with CorporateStack’s operational security procedures.

10.2 Disaster Recovery

CorporateStack maintains a geographically separate Disaster Recovery (DR) environment located in Frankfurt, Germany, supporting the recovery of services hosted within Oracle Cloud Infrastructure (OCI) primary regions in the United Arab Emirates (UAE) and the Kingdom of Saudi Arabia (KSA). Disaster recovery procedures are activated where a significant operational event materially affects the availability of the primary production environment.

10.3 Recovery Objectives

CorporateStack maintains documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) appropriate to the Services provided.

Service CommitmentTarget
Recovery Time Objective (RTO)Within 24 Hours
Recovery Point Objective (RPO)Within 24 Hours

The above objectives represent CorporateStack’s operational recovery targets following a declared disaster affecting the primary production environment.

10.4 Disaster Recovery Testing

CorporateStack periodically reviews and validates its disaster recovery capabilities to help ensure the continued effectiveness of its recovery procedures and operational readiness. Testing activities are performed as part of CorporateStack’s ongoing Business Continuity program and continuous service improvement initiatives.

10.5 Customer Communication

Where a disaster recovery event materially affects the Services, CorporateStack will communicate with affected customers regarding:

  • Service status;
  • Recovery progress;
  • Expected restoration activities (where reasonably available); and
  • Confirmation when normal operations have been restored.
10.6 Relationship to Other Documents

This section should be read together with the:

  • CorporateStack Business Continuity & Disaster Recovery (BCDR) Overview;
  • CorporateStack Data Processing Addendum (DPA);
  • CorporateStack Security & Compliance Overview; and
  • CorporateStack Enterprise End User License Agreement (EULA).
10.7 Key Business Continuity Commitments
  • Automated Encrypted Backups
  • Geographically Separate Disaster Recovery Site
  • Documented Recovery Procedures
  • Recovery Time Objective (RTO)
  • Recovery Point Objective (RPO)
  • Periodic Disaster Recovery Testing
  • Customer Communication During Recovery Events

11. Service Credits

CorporateStack is committed to meeting the Service Availability commitments set out in this Service Level Agreement. Where CorporateStack fails to achieve the applicable monthly Service Availability commitment, the Customer may be eligible to receive Service Credits in accordance with this Section. Service Credits are intended as a reasonable commercial remedy for qualifying service availability failures and shall constitute the Customer’s sole and exclusive remedy for any failure to achieve the applicable Service Availability commitment.

11.1 Service Credit Eligibility

Service Credits apply only where:

  • The monthly Service Availability falls below the committed availability level;
  • The affected Services are covered by this SLA;
  • The service interruption is not attributable to any SLA exclusion set out in this Agreement; and
  • The Customer submits a written Service Credit request within thirty (30) calendar days following the end of the applicable calendar month. CorporateStack reserves the right to verify all Service Credit claims against its operational monitoring records.
11.2 Service Credit Schedule
Monthly Service AvailabilityService Credit
99.90% or higherNo Service Credit
99.00% – 99.89%3% of the affected monthly Subscription Fee
95.00% – 98.99%5% of the affected monthly Subscription Fee
Below 95.00%10% of the affected monthly Subscription Fee

Service Credits shall be calculated solely on the monthly Subscription Fees applicable to the affected Services.

11.3 Application of Service Credits

Approved Service Credits shall be applied as a credit against future Subscription Fees and shall not be paid as cash refunds. Service Credits may not be transferred, assigned, or redeemed for cash.

11.4 Exclusions

Service Credits shall not apply where the service interruption results from:

  • Planned Maintenance;
  • Emergency Maintenance;
  • Force Majeure events;
  • Customer-controlled infrastructure, systems, or configurations;
  • Third-party services outside CorporateStack’s operational control;
  • Customer misuse, unauthorized modifications, or failure to comply with CorporateStack’s documented requirements;
  • Suspension of Services in accordance with the applicable agreement; or
  • Any circumstance expressly excluded under this SLA.
11.5 Sole Remedy

Except where otherwise required by applicable law, the Service Credits described in this Section constitute the Customer’s sole and exclusive remedy for any failure by CorporateStack to achieve the applicable Service Availability commitment. Nothing in this Section limits either party’s rights or remedies arising from matters outside the scope of the Service Availability commitments, including obligations under the Enterprise End User License Agreement (EULA), the Data Processing Addendum (DPA), or applicable law.

11.5.1 Key Service Credit Principles

Transparent Availability Commitments Objective Credit Calculation Future Subscription Fee Credits Clearly Defined Eligibility Criteria Standard SLA Exclusions Enterprise SaaS Industry Practice

12. Customer Responsibilities & Dependencies

CorporateStack’s ability to meet the service commitments set out in this Service Level Agreement depends upon the Customer fulfilling its responsibilities under the applicable agreement and cooperating reasonably during service delivery, incident investigation, and support activities. Failure by the Customer to meet these responsibilities may impact CorporateStack’s ability to achieve the applicable service commitments.

12.1 Customer Responsibilities

The Customer shall:

  • Designate authorized business and technical contacts for communications with CorporateStack.
  • Maintain accurate user, administrator, and contact information.
  • Protect user credentials and implement appropriate internal access controls.
  • Enable Multi-Factor Authentication (MFA), where available and appropriate.
  • Maintain supported internet connectivity, endpoint devices, and local network infrastructure.
  • Ensure that Customer-managed systems, integrations, and third-party services are properly maintained.
  • Promptly report Incidents through CorporateStack’s authorized support channels.
  • Provide sufficient information to enable CorporateStack to investigate and resolve reported issues.
  • Cooperate with reasonable troubleshooting, testing, and validation activities.
  • Promptly review and confirm the resolution of Incidents and Service Requests.
12.2 Customer Data

The Customer remains solely responsible for:

  • The accuracy, completeness, and legality of Customer Data.
  • Maintaining appropriate internal data governance and retention policies.
  • Obtaining all necessary rights, permissions, and consents relating to Customer Data.
  • Ensuring that Customer Data does not violate applicable laws or third-party rights.
12.3 Customer Dependencies

CorporateStack’s service commitments assume that the Customer:

  • Uses supported browsers and client software.
  • Maintains stable internet connectivity.
  • Operates compatible third-party integrations.
  • Provides timely responses where Customer action or approval is required.
  • Does not interfere with the normal operation of the Services. Delays resulting from Customer actions, inaction, third-party systems, or dependencies outside CorporateStack’s reasonable control shall not be considered a failure by CorporateStack to meet the service commitments under this SLA.
12.4 Shared Responsibility

CorporateStack operates under a shared responsibility model for cloud services. CorporateStack is responsible for securing, operating, and maintaining the managed SaaS platform, while the Customer remains responsible for the secure administration and appropriate use of the Services within its own organization. Further information regarding the shared responsibility model is available in the CorporateStack Security & Compliance Overview.

12.5 Key Customer Responsibilities
  • Authorized Customer Contacts
  • User & Access Management
  • Endpoint & Network Security
  • Accurate Customer Data
  • Timely Incident Reporting
  • Customer Cooperation
  • Shared Responsibility for Secure Service Operation

13. SLA Exclusions

The service commitments, response targets, restoration targets, service availability commitments, and Service Credits set out in this Service Level Agreement apply only to the CorporateStack Services operating under normal supported conditions. CorporateStack shall not be considered in breach of this SLA, nor shall Service Credits apply, where any failure to meet the service commitments results from circumstances outside CorporateStack’s reasonable control.

13.1 Excluded Events

This SLA does not apply to service interruptions, delays, or degradation resulting from:

  • Planned Maintenance carried out in accordance with this SLA;
  • Emergency Maintenance necessary to protect the security, integrity, availability, or stability of the Services;
  • Force Majeure events;
  • Internet service provider or telecommunications failures;
  • Customer-controlled infrastructure, networks, endpoint devices, or internet connectivity;
  • Customer configuration errors, misuse, unauthorized modifications, or failure to follow CorporateStack’s documented requirements;
  • Customer-managed integrations, third-party software, hardware, or services outside CorporateStack’s operational control;
  • Delays resulting from Customer actions, approvals, or failure to provide reasonably requested information;
  • Suspension of the Services in accordance with the applicable agreement, including for non-payment or security-related reasons;
  • Beta, preview, pilot, demonstration, testing, sandbox, or non-production environments; or
  • Events caused by malicious activity originating from the Customer’s environment, including malware, unauthorized access, or denial-of-service attacks not attributable to CorporateStack.
13.2 Third-Party Dependencies

CorporateStack is not responsible for failures, interruptions, or performance degradation arising from third-party products or services that are not owned, managed, or operated by CorporateStack. Where reasonably practicable, CorporateStack will cooperate with the Customer to assist in identifying and coordinating the resolution of issues involving third-party providers.

13.3 Customer Non-Compliance

Service commitments under this SLA may be suspended or reasonably adjusted where the Customer fails to:

  • Comply with its obligations under the applicable agreement;
  • Maintain supported operating environments;
  • Cooperate with incident investigation and resolution activities; or
  • Meet the Customer Responsibilities set out in this SLA.
13.4 Relationship to Applicable Agreements

Nothing in this Section limits either party’s rights or obligations under the applicable Sales Order, the CorporateStack Enterprise End User License Agreement (EULA), the Data Processing Addendum (DPA), or applicable law.

13.4.1 Key SLA Exclusions

Planned & Emergency Maintenance Force Majeure Customer-Controlled Infrastructure Third-Party Services Customer Misuse or Misconfiguration Customer Delays or Non-Cooperation Non-Production Environments Lawful Service Suspension

14. Reporting, Governance & Continuous Improvement

CorporateStack is committed to continuously monitoring, reviewing, and enhancing the quality, availability, and performance of the Services. Operational performance is regularly assessed through service monitoring, incident analysis, customer feedback, and operational reviews to support ongoing service improvement and customer satisfaction.

14.1 Service Performance Reporting

CorporateStack maintains operational records and service metrics to monitor compliance with the commitments set out in this Service Level Agreement. Where applicable, service performance reports may include:

  • Service Availability;
  • Incident volumes and trends;
  • Initial Response performance;
  • Service Restoration performance;
  • Major Incident summaries;
  • Planned maintenance activities;
  • Service Credit eligibility (where applicable); and
  • Operational improvement initiatives. Service reports may be provided to enterprise customers upon request or as otherwise agreed under the applicable commercial agreement.
14.2 Service Reviews

For enterprise customers, CorporateStack may conduct Quarterly Service Review (QSR) meetings to review operational performance and strengthen the ongoing partnership. Quarterly Service Reviews may include:

  • Review of SLA performance;
  • Service availability metrics;
  • Incident and problem trends;
  • Customer feedback;
  • Planned product enhancements;
  • Operational risks and mitigation activities; and
  • Opportunities for continuous improvement.
14.3 Continuous Service Improvement

CorporateStack continually reviews its operational processes, service management practices, security controls, and customer feedback to enhance the quality and resilience of the Services. Improvement initiatives may include:

  • Platform performance optimization;
  • Security enhancements;
  • Infrastructure improvements;
  • Operational process refinement;
  • Product enhancements; and
  • Customer experience improvements.
14.4 SLA Review

This Service Level Agreement may be periodically reviewed and updated by CorporateStack to reflect changes in:

  • Service offerings;
  • Operational capabilities;
  • Technology platforms;
  • Regulatory requirements; or
  • Industry best practices. Any material updates to this SLA will apply prospectively and will not materially reduce the level of service commitments applicable during an active subscription term without prior notice to the Customer.
14.4.1 Key Governance Principles

Operational Performance Monitoring Quarterly Service Reviews (QSR) Continuous Service Improvement Service Performance Reporting Customer Feedback Integration Periodic SLA Review Enterprise Service Governance

15. Relationship to Other CorporateStack Governance Documents

This Service Level Agreement (SLA) forms part of CorporateStack’s enterprise governance framework and should be read together with the applicable contractual and operational documents governing the Customer’s use of the Services. The following documents complement this SLA and collectively define the legal, operational, security, and privacy commitments applicable to the Services:

DocumentPurpose
Sales OrderDefines the commercial terms, subscribed services, pricing, subscription term, and any customer-specific commercial commitments.
Enterprise End User License Agreement (EULA)Governs licensing rights, permitted use, intellectual property, warranties, liability, and general contractual terms.
Data Processing Addendum (DPA)Defines the obligations relating to the processing of Personal Data and compliance with applicable Data Protection Laws.
Privacy StatementDescribes how CorporateStack collects, uses, stores, and protects personal information.
Security & Compliance OverviewProvides an overview of CorporateStack’s security framework, operational controls, and compliance practices.
Business Continuity & Disaster Recovery (BCDR) OverviewDescribes CorporateStack’s business continuity strategy, backup processes, disaster recovery capabilities, and recovery framework.
15.1 Order of Precedence

In the event of any inconsistency between CorporateStack’s governance documents, the following order of precedence shall apply unless otherwise expressly agreed in writing: Executed Sales Order; Customer-specific written amendments or addenda (if applicable); CorporateStack Enterprise End User License Agreement (EULA); CorporateStack Data Processing Addendum (DPA); This Service Level Agreement (SLA); CorporateStack Privacy Statement; CorporateStack Security & Compliance Overview; CorporateStack Business Continuity & Disaster Recovery (BCDR) Overview. Informational documents, including the Security & Compliance Overview and the Business Continuity & Disaster Recovery (BCDR) Overview, are intended to describe CorporateStack’s operational practices and do not create additional contractual obligations beyond those expressly set out in the applicable agreement.

15.2 Document Review

CorporateStack periodically reviews its governance documentation to reflect changes in applicable laws, technology, operational practices, security requirements, and customer needs. The latest versions of CorporateStack’s customer-facing governance documents are available through the CorporateStack website and Trust Center.