Service Level Agreement
Last updated September 2, 2026
This Service Level Agreement (“SLA”) is part of the Terms of Service. It states the edge availability target we commit to and the service credits we will issue if we miss it. If this page and the Terms conflict, the Terms control except that the numbers and credit math on this page govern the remedy.
1. What this covers
This SLA covers edge / WAF availability for a site that is Live — visitor traffic is flowing through the Amazon CloudFront + AWS WAF shield we provisioned, whether rules are in count or block.
A minute is available when the shield can return a valid response path: CloudFront accepts the request and AWS WAF can evaluate it (and forward it to your origin or return a WAF response). A minute is downtime when the edge fails to do that for a reason we control, as determined from our CloudFront metrics and logs for that site's distribution.
2. What this does not cover
The following are out of scope. They do not count as downtime under this SLA:
- Your origin is down, overloaded, misconfigured, or returning errors.
- Your DNS, registrar, or nameserver mistakes, or records that no longer point at the shield.
- The site is not yet Live — ACM/TLS or DNS cutover still pending.
- Unpaid accounts, failed payments, trial that has not converted, cancelled or suspended protection, or a lapsed subscription.
- Scheduled maintenance announced by email to your account address at least 24 hours in advance.
- AWS or CloudFront regional or global outages (they are the substrate; we sit on them).
- Volumetric attacks that exceed the included 300 GB / 5 million-request allowance for the site, unless you have paid the documented overage for that month.
- Legal takedowns, court orders, or abuse suspensions.
- False positives, blocked legitimate traffic, or any security outcome — a WAF is not a promise that every attack is stopped.
- The dashboard, billing portal, marketing site, or email delivery.
- Malware cleanup, PCI certification, or 100% uptime — we do not offer those.
3. Target
99.9% of in-scope minutes in each calendar month, measured in UTC. In a 30-day month that is 43.2 minutes of allowed in-scope downtime (30 × 24 × 60 × (1 − 99.9/100)).
4. How we measure
We do not publish a public status page for customer edges, and we do not treat third-party uptime robots as the source of truth.
Credits are based on our CloudFront metrics and logs for that site's distribution — specifically CloudFront 5xx attributable to the edge or distribution, not origin-generated 5xx. You email us a UTC window; we compare that window to those logs and AWS metrics and reply with the calculated in-scope availability. There is no automated probe fleet and no self-serve credit button in this version.
5. Service credits
If monthly in-scope availability for a Live site falls below 99.9%, we will issue a service credit on the next invoice for that site — not cash, not a refund of amounts already paid. Credits are the sole and exclusive remedy for a miss of this target. They do not change the rest of the refund language in the Terms.
- Below 99.9% but at least 99.0%: 10% of that site's monthly fee.
- Below 99.0% but at least 95.0%: 25% of that site's monthly fee.
- Below 95.0%: 50% of that site's monthly fee (the cap).
The credit is capped at 50% of that site's monthly fee for the affected month. The monthly fee is the recurring subscription amount allocated to that site for that month (the volume unit rate if you are on volume pricing; for annual plans, one-twelfth of the annual site fee). Overage charges are not credited. At the $150 list monthly rate, a 10% credit is $15.
To request a credit, email support@wafcybersecurity.com within 30 days after the calendar month ends (UTC). Include the domain, the UTC start and end of the window, and a short description. We review the logs and apply any credit manually on the next invoice. Late requests may be denied.
6. Security is not uptime
This SLA is about the edge returning a valid response path. It is not a guarantee that every attack will be blocked, that a rule will never false-positive, or that your origin or application will stay up. Those remain your responsibility, with our help on the WAF.
7. Governing law
This SLA is governed by the laws of the State of North Carolina, on the same terms as the Terms of Service. Questions: support@wafcybersecurity.com.