Control plane
SLA 99.5% / month
98.89%
Apr 25, 2026
2026-07-23
SLA targets and recent operational history for the six subsystems that make up Penaxtra. 90-day uptime grid below; incident notifications go to the subscribed contact on every active workspace.
Last refreshed:
Each bar is one day. Green is fully operational, amber is a partial (sub-day) outage, red is a full-day outage. Hover a bar to read the date.
Web console, public API, and authentication services. SLA target: 99.5% monthly.
Customer-deployed agent. Autonomous; continues forwarding traffic with the last signed rule blob even when the control plane is unreachable.
Adversarial probe execution and judge orchestration. SLA target: 99% scan completion within stated window.
Managed relational database with hot standby. SLA target: 99.9% availability, point-in-time recovery to any minute in the last 7 days.
Managed work queue. Carries scheduled scans, report generation, and webhook fanout.
EU object storage with age-encrypted off-site backup. Reports are retained for the tenant-configured window.
99.5% monthly availability on the public console and API. Maintenance windows are announced at least 72 hours in advance and excluded from the calculation.
99.9% monthly availability with hot standby failover under 30 seconds. Point-in-time recovery to any minute within the last seven days.
Critical incidents are posted to this page within fifteen minutes of detection. Customers on Business and Enterprise tiers receive email notifications; Enterprise tier additionally receives Slack or webhook notifications.
Falling below the SLA in a billing month triggers a service credit of ten percent for the first hour past target, then one percent per additional hour, capped at fifty percent of the monthly fee. Enterprise contracts may negotiate alternative remedies.
Duration: about 1 hour. Scope: Runtime gateway only. Customer impact: While we rolled out a new gateway agent build, deployed agents could not reach the control plane to pull an updated signed rule blob for roughly an hour. Agents kept forwarding traffic on their last signed blob, so enforcement stayed in effect and no prompt content was lost. No other subsystem was affected.
We resolved it by rolling the agent build forward to a fixed version, and we have added a staged rollout step so a single bad agent build can no longer interrupt rule-blob fetches across the fleet. Control plane, scan workers, database, and job queue were healthy throughout.
Duration: 24 hours. Scope: Control plane (web console, public API) and managed relational database. Customer impact: Scheduled scans deferred; runtime gateways continued forwarding traffic autonomously with the last signed rule blob; no customer prompt content was lost.
The orchestrator's quorum probe relied on a single network path that became congested during a regional carrier event. The probe interpreted the congestion as a partial split-brain and refused to promote the standby. The fix was to add a second quorum path through an alternate VPC peering link and to require both paths to agree before refusing automated failover.
Subscribe with a work email; we ship a one-line status digest when a subsystem flips. No marketing in this channel.
One short message per incident. Unsubscribe in one click.