Enterprise
Service Level Agreement
This page describes the service level framework that applies to Paycux enterprise accounts: which services are covered, how availability is measured, how incidents are classified and escalated, and how service credits are claimed.
Availability objectives, request thresholds, credit percentages and response targets are agreed per contract and set out in your order form. No number on this page substitutes for the one in your agreement; where the two differ, the agreement governs.
Scope
What the agreement covers
Covered Services are the products named in your enterprise agreement. Everything below is eligible; what applies to you depends on what you have switched on.
Authentication and sessions
Sign-up, sign-in, session issuance and refresh through AuthKit and the User Management API.
Enterprise SSO
SAML and OIDC authorization requests handled on behalf of your customers' identity providers.
Directory Sync
Inbound SCIM traffic from identity providers, and the events Paycux emits from it.
Audit Logs
Event ingestion, retention, dashboard search, export and streaming to your own systems.
Definitions
How availability is measured
These terms carry the meaning below wherever they appear in your agreement.
- Covered Service
- Any service or product Paycux has agreed to provide to you under an enterprise agreement. Products designated alpha, beta or preview are not Covered Services unless your agreement says otherwise in writing.
- Valid Request
- An HTTP request that matches the Paycux documentation and would normally result in a non-error response. For Directory Sync, a Valid Request is a valid request made by a SCIM identity provider to Paycux. Repeated idempotent requests count as one Valid Request.
- Error Rate
- The number of Valid Requests answered with an HTTP 5xx status, divided by the total number of Valid Requests in the period. Repeated identical responses do not count more than once.
- Downtime
- An Error Rate for a Covered Service above the threshold set out in your agreement.
- Downtime Period
- A period of Downtime for a Covered Service where the volume of Valid Requests meets the request threshold in your agreement. Intermittent Downtime shorter than one full period is not counted.
- Monthly Uptime Percentage
- Total minutes in the month, minus the minutes contained in all Downtime Periods that month, divided by the total minutes in the month.
- Service Credits
- A percentage of your monthly billing for Covered Services, applied against future payments when the Monthly Uptime Percentage falls below the objective. The objective and the corresponding credit percentages are set out in your agreement.
Support channels
How to reach someone who can act
Enterprise accounts get more than an inbox. Each channel below reaches people who can read your logs and change the system.
Dedicated Slack channel
A shared channel with the engineers who operate the services you depend on. The first place to raise anything urgent.
In-product web support
Raise an issue from the dashboard with your environment, connection and recent requests already attached.
Email support
For anything that is not time-critical, and for the written record when a thread needs one.
Technical account manager
A named contact who knows your integration, runs the review cadence, and owns escalation on your behalf.
Incident severity
Four levels, agreed in writing
Severity drives who is paged and how often you hear from us. It is assigned at triage and can be changed by agreement on the thread.
Critical
A Covered Service is unavailable or materially degraded in production, and there is no workaround. Your users cannot sign in.
- Authentication requests failing across a production environment
- SSO authorization broken for one or more enterprise connections
- Suspected security incident affecting your data
High
A production feature is impaired or a workaround exists but is not sustainable. Business impact is real but contained.
- Directory Sync events delayed beyond the expected window
- Audit Log streaming to your SIEM interrupted
- A single connection failing while the rest are healthy
Normal
A non-critical defect, a question about behaviour, or an issue confined to a staging environment.
- Unexpected field in an API response
- Admin Portal styling or copy problem
- Configuration question during an integration
Low
A cosmetic issue, documentation gap, or a feature request with no operational impact.
- Missing example in the docs
- Enhancement request for a dashboard view
- Planning question about an upcoming migration
Response targets for each level are agreed per contract. Round-the-clock coverage is available on the Enterprise support plan.
Escalation path
What happens after you report it
Every step below has an owner. You never need to guess who is holding the issue.
- 1
Raise
Report the issue in the Slack channel, from the dashboard, or by email. Include the environment, the affected connection, and a request identifier if you have one.
- 2
Triage and severity
Paycux acknowledges the report and assigns a severity level. If you disagree with the level, say so on the thread — severity is adjusted by agreement, not unilaterally.
- 3
Engineering engagement
For P1 and P2 the on-call engineer for the affected service is paged directly and joins the thread. Updates continue on a fixed cadence until the issue is downgraded.
- 4
Management escalation
Your technical account manager can escalate to engineering leadership at any point, and you can request that escalation yourself without justifying it.
- 5
Post-incident review
After a P1, Paycux produces a written review covering the timeline, the cause, the customer impact, and the remediation with owners and dates.
Service credits
Requesting a credit
To receive Service Credits you must notify Paycux support within the calendar month following the Downtime, and supply the dates and times of the Downtime Periods you are claiming for.
- Claims are assessed against the objective and thresholds in your agreement.
- Where the Monthly Uptime Percentage is disputed, Paycux determines it in good faith from its system logs, monitoring and historic usage patterns.
- Paycux may ask for your own log files covering the Downtime Periods; if they are not provided, the claim for those periods lapses.
- Unless your agreement says otherwise, Service Credits are your sole and exclusive remedy for Downtime.
Restrictions
What is out of scope
The commitments apply to production use of the Paycux platform. The agreement does not apply in the following cases.
- Non-production environments, including staging and sandbox.
- Features or products designated alpha, beta or preview without prior written approval.
- Usage that places an unreasonable or disproportionate load on Paycux infrastructure without prior written approval.
- Downtime while your right to use the service is suspended or terminated under the terms of service, acceptable use policy, or a government or court order.
- Faults originating outside the Paycux service, including your own connectivity, internet service providers, third-party identity providers, and customer-managed services.
- Force majeure events such as natural disasters, acts of war, government requests and wide-area internet disruption.
- Planned maintenance for which advance written notice was given.
- Emergency maintenance carried out in the interest of customers or Covered Services, such as patching a disclosed vulnerability.
Contact
Questions about this agreement go to Paycux support. For the commercial terms behind it, ask your account contact or start a conversation with sales.
Put the commitments in writing before you need them
Enterprise agreements are negotiated, not generated. Tell us what your own customers hold you to and we will work from there.