Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Platform status and availability.

SLA targets and recent operational history for the six subsystems that make up Penaxtra. 90-day uptime grid below; incident notifications go to the subscribed contact on every active workspace.

Last refreshed:

98.84% 90-day overall uptime 88 of 90 days fully operational, 1 partial
2 Recorded incidents Latest: · Runtime gateway, 1h
Operational Current state All six subsystems healthy

Subsystem uptime, oldest to newest.

Each bar is one day. Green is fully operational, amber is a partial (sub-day) outage, red is a full-day outage. Hover a bar to read the date.

Control plane SLA 99.5% / month 98.89%
Apr 25, 2026 2026-07-23
Runtime gateway autonomous, n/a SLA 99.95%
Apr 25, 2026 2026-07-23
Scan workers SLA 99% completion 100.00%
Apr 25, 2026 2026-07-23
Database SLA 99.9% / month 98.89%
Apr 25, 2026 2026-07-23
Job queue SLA 99% / month 100.00%
Apr 25, 2026 2026-07-23
Report storage SLA 99.9% durability 100.00%
Apr 25, 2026 2026-07-23

Live state per subsystem.

Control plane Operational

Web console, public API, and authentication services. SLA target: 99.5% monthly.

Runtime gateway Operational

Customer-deployed agent. Autonomous; continues forwarding traffic with the last signed rule blob even when the control plane is unreachable.

Scan workers Operational

Adversarial probe execution and judge orchestration. SLA target: 99% scan completion within stated window.

Database Operational

Managed relational database with hot standby. SLA target: 99.9% availability, point-in-time recovery to any minute in the last 7 days.

Job queue Operational

Managed work queue. Carries scheduled scans, report generation, and webhook fanout.

Report storage Operational

EU object storage with age-encrypted off-site backup. Reports are retained for the tenant-configured window.

What we commit to. What you do when we miss it.

Control plane uptime

99.5% monthly availability on the public console and API. Maintenance windows are announced at least 72 hours in advance and excluded from the calculation.

99.5% / month72h notice

Database availability

99.9% monthly availability with hot standby failover under 30 seconds. Point-in-time recovery to any minute within the last seven days.

99.9% / monthPITR 7 days

Incident notification

Critical incidents are posted to this page within fifteen minutes of detection. Customers on Business and Enterprise tiers receive email notifications; Enterprise tier additionally receives Slack or webhook notifications.

15 min post-detectEmail + Slack + webhook

Service credit

Falling below the SLA in a billing month triggers a service credit of ten percent for the first hour past target, then one percent per additional hour, capped at fifty percent of the monthly fee. Enterprise contracts may negotiate alternative remedies.

Self-claimCapped 50%

Two recorded incidents in the last 90 days.

Low

Runtime gateway briefly unavailable during an agent update

Duration: about 1 hour. Scope: Runtime gateway only. Customer impact: While we rolled out a new gateway agent build, deployed agents could not reach the control plane to pull an updated signed rule blob for roughly an hour. Agents kept forwarding traffic on their last signed blob, so enforcement stayed in effect and no prompt content was lost. No other subsystem was affected.

We resolved it by rolling the agent build forward to a fixed version, and we have added a staged rollout step so a single bad agent build can no longer interrupt rule-blob fetches across the fleet. Control plane, scan workers, database, and job queue were healthy throughout.

High

Control plane unreachable; database failover delayed

Duration: 24 hours. Scope: Control plane (web console, public API) and managed relational database. Customer impact: Scheduled scans deferred; runtime gateways continued forwarding traffic autonomously with the last signed rule blob; no customer prompt content was lost.

Timeline

  • 00:00 UTC · Primary database node experienced sustained replication lag from the hot standby. Automated failover triggered but was rolled back by the orchestrator after a quorum probe returned inconsistent state.
  • 00:18 UTC · Page-out alarm hit the on-call rotation. Public status page flipped to "Investigating".
  • 02:40 UTC · Manual failover executed against the hot standby after pinning the orchestrator's quorum check to a single region. Public API recovered. Scan workers resumed dequeueing.
  • 03:10 UTC · Background reconciliation completed; lag returned to baseline.
  • +24h · Internal post-incident review concluded; remediation actions filed.

Root cause

The orchestrator's quorum probe relied on a single network path that became congested during a regional carrier event. The probe interpreted the congestion as a partial split-brain and refused to promote the standby. The fix was to add a second quorum path through an alternate VPC peering link and to require both paths to agree before refusing automated failover.

Remediation

  • Second quorum path deployed in production; rolled out the week after the incident.
  • Runtime gateway tested under control-plane outage; confirmed autonomous operation for at least 72 hours with the last signed rule blob.
  • Status page now updates within 15 minutes of detection; incident notification email opt-in surfaced on every tenant onboarding.

Want incident notifications?

Subscribe with a work email; we ship a one-line status digest when a subsystem flips. No marketing in this channel.

One short message per incident. Unsubscribe in one click.