Service Level Agreement (SLA) Template
Version: 2.0 | Effective: July 15, 2026 | Status: Template β Execute per engagement
β οΈ How to Use This Template
- This SLA is incorporated by reference into the Service Agreement (MSA/SoW) between CyberSpeed LLC ("Provider") and the Client ("Customer").
- Complete all [BRACKETED FIELDS] with engagement-specific metrics, thresholds, and contact details.
- Both parties sign the Service Agreement; this SLA becomes legally binding upon execution.
- Attach Annex A (Service Definitions), Annex B (Monitoring & Reporting), and Annex C (Escalation Matrix).
- Review quarterly; amend via Change Control per Section 12.
SERVICE LEVEL AGREEMENT
Between
| Provider: | CyberSpeed LLC |
| FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE | |
| Trade Licence No.: [PROVIDER TRADE LICENCE NUMBER] | |
| Customer: | [CUSTOMER LEGAL ENTITY NAME] |
| Address: [CUSTOMER REGISTERED ADDRESS] | |
| Trade Licence No.: [CUSTOMER TRADE LICENCE NUMBER] |
(collectively, the "Parties"; each a "Party")
Effective Date: [EFFECTIVE DATE] | Term: [INITIAL TERM, e.g., 12 months] | Auto-renewal: [YES/NO, period]
1. Purpose & Scope
- This SLA defines the service levels, performance metrics, responsibilities, and remedies for the Services described in the Service Agreement and Annex A (Service Definitions).
- Applies to: [LIST SPECIFIC SERVICES, e.g., Web App Hosting, SEO Platform, Shopify Store, AI API, Ad Management Dashboard, Expert Portal].
- Exclusions: Customer applications/code, third-party platforms (Shopify, Google, Meta, etc.), Customer premise equipment, force majeure events (Section 14).
- In case of conflict: Service Agreement > This SLA > Annexes.
2. Service Availability (Uptime)
2.1 Availability Targets
| Service Tier | Monthly Uptime % | Max Downtime/Month | Measurement |
|---|---|---|---|
| Critical (Production APIs, Ecommerce, AI Inference) | 99.9% | 43 min 12 sec | Synthetic monitoring (5-min intervals, 3 regions) |
| Standard (Staging, Internal Tools, Reporting) | 99.5% | 3 hr 39 min | Synthetic monitoring (10-min intervals) |
| Development (Dev/QA Environments) | 99.0% | 7 hr 18 min | Best effort |
2.2 Exclusions from Downtime
- Scheduled maintenance (notified β₯ 72 hours, max 4 hrs/month, off-peak: Fri 02:00β06:00 GST)
- Force majeure (Section 14)
- Customer-caused issues (misconfiguration, credential expiry, quota exceeded)
- Third-party platform outages (Shopify, Google, Meta, OpenAI, cloud provider beyond Provider's control)
- DNS propagation, ISP issues, Client-side network
2.3 Service Credits for Availability Breach
| Actual Uptime | Service Credit (% of Monthly Recurring Fee) |
|---|---|
| < Target but β₯ Target β 0.5% | 5% |
| < Target β 0.5% but β₯ Target β 1.0% | 10% |
| < Target β 1.0% but β₯ Target β 2.0% | 20% |
| < Target β 2.0% | 30% (max per month) |
Credits: Requested in writing within 15 days of month-end. Applied as invoice credit. Not refundable. Sole remedy for availability breaches.
3. Response & Resolution Times (Support)
3.1 Incident Priority Definitions
| Priority | Definition | Examples |
|---|---|---|
| P1 β Critical | Service unavailable, data loss, security breach, revenue-impacting outage affecting all users | Production API down, Ecommerce checkout broken, AI inference failing, Data breach suspected |
| P2 β High | Major functionality impaired, significant performance degradation, subset of users affected | Slow page loads (>5s), Partial feature failure, Integration errors affecting one channel |
| P3 β Medium | Minor functionality issue, cosmetic bug, non-critical feature unavailable | UI alignment, Report formatting, Non-critical automation failing |
| P4 β Low | Enhancement request, documentation, general inquiry, cosmetic issue | Feature request, Documentation update, Access provisioning |
3.2 Response & Resolution Targets (Business Hours: MonβThu, Sun 09:00β18:00 GST; Fri 09:00β12:00)
| Priority | First Response | Status Update Frequency | Resolution Target | Escalation |
|---|---|---|---|---|
| P1 | 15 minutes | Every 30 minutes | 4 hours | Immediate to Engineering Lead β CTO (30 min) |
| P2 | 1 hour | Every 2 hours | 8 business hours | Engineering Lead (2 hrs) β CTO (4 hrs) |
| P3 | 4 business hours | Daily | 5 business days | Team Lead (24 hrs) |
| P4 | 1 business day | Weekly | Next planned release / 30 days | Product Manager |
3.3 After-Hours Support (Optional Add-On)
- 24/7 P1-only coverage: +25% of monthly fee. P1 response: 30 min. On-call rotation.
- Emergency hotline: +971 4 200 0000 (option 9) / WhatsApp priority queue.
3.4 Service Credits for Missed Resolution Targets
| Priority | Missed Target By | Credit per Incident |
|---|---|---|
| P1 | > 2x target | 10% monthly fee |
| P2 | > 2x target | 5% monthly fee |
| P3 | > 2x target | 2% monthly fee |
Max 20% monthly fee across all credits. Credits requested within 15 days.
4. Performance Metrics (Beyond Availability)
| Metric | Target | Measurement | Reporting |
|---|---|---|---|
| API Latency (p95) | < 200ms (Critical), < 500ms (Standard) | APM (Datadog/New Relic) 5-min rollups | Monthly |
| API Error Rate | < 0.1% (5xx), < 1% (4xx client) | APM / Load balancer logs | Monthly |
| AI Inference Latency (p95) | < 500ms (Standard), < 200ms (Optimized) | Provider-side tracing | Monthly |
| Build/Deploy Pipeline Success | > 95% | CI/CD system (GitHub Actions/GitLab) | Monthly |
| Backup Restore Test | Quarterly success | Automated DR drill | Quarterly |
| Security Patch Application | Critical: 48h, High: 7d | Vuln scanner + patch management | Monthly |
| SSL Certificate Expiry | 0 expired certs | Automated monitoring (30/14/7 day alerts) | Monthly |
5. Monitoring, Reporting & Reviews
5.1 Monitoring
- Provider maintains 24/7 monitoring: infrastructure (CloudWatch/Datadog), application (APM), synthetic (Pingdom/Checkly), security (WAF/SIEM).
- Customer receives read-only access to status dashboard:
status.cyberspeedllc.com(or Customer-specific).
5.2 Reporting
| Report | Frequency | Delivery | Content |
|---|---|---|---|
| SLA Performance Report | Monthly (by 5th business day) | Email + Dashboard | Uptime, incidents, credits, trends, upcoming maintenance |
| Incident Post-Mortem (P1/P2) | Within 5 business days of resolution | Email + Confluence/Notion | Root cause, timeline, action items, prevention |
| Security Scan Summary | Monthly | Dashboard | Vuln counts, patch status, compliance |
| Capacity & Utilisation | Quarterly | Meeting + Report | CPU/Memory/Storage/Network trends, forecast, scaling plan |
| Quarterly Business Review (QBR) | Quarterly | Video call (60 min) | SLA performance, roadmap, risk register, cost optimisation |
6. Change Management
- All changes to production follow ITIL-aligned Change Advisory Board (CAB) process.
- Standard Changes (pre-approved, low risk): Deployed any time per runbook. No approval needed.
- Normal Changes: Submitted β₯ 5 business days, CAB approval, risk assessment, rollback plan.
- Emergency Changes (P1/P2 remediation): Authorised by Engineering Lead + Customer stakeholder (verbal/email), post-implementation review within 48h.
- Customer notified of Normal/Emergency changes affecting their Services.
- Maintenance windows: Fri 02:00β06:00 GST (max 4 hrs/month scheduled). Emergency windows as needed with 2h notice.
7. Security & Compliance
- Provider maintains ISO 27001-aligned ISMS (certification target Q4 2026).
- Annual penetration test (CREST-certified), quarterly vulnerability scans, monthly patching.
- Data residency: UAE (Azure UAE North / AWS ME / GCP Dubai). Subprocessor locations per DPA Annex C.
- Encryption: AES-256 at rest, TLS 1.3 in transit, customer-managed keys option.
- Access control: Zero-trust, MFA, RBAC, PAM, quarterly access reviews.
- Incident response: 24/7, 72h regulatory notification (UAE Data Office / DIFC Commissioner / ADGM Registrar).
- Compliance: UAE PDPL, DIFC DP Law, ADGM DP Regs, GDPR (where applicable), PCI DSS SAQ-A (if payment processing).
8. Data Protection & DPA
Personal Data processing governed by the Data Processing Agreement (DPA) executed between Parties. Provider acts as Processor; Customer as Controller. Key commitments:
- Processing only per Customer instructions (Service Agreement, DPA, ticketing system).
- Subprocessors per DPA Annex C (30-day notice for new subprocessors).
- Data Subject rights assistance (48h notification of direct requests).
- Breach notification: 24h to Customer, 72h to supervisory authority.
- Return/deletion of Personal Data within 30 days post-termination.
9. Customer Responsibilities
- Provide timely access, credentials, approvals, and stakeholder availability.
- Maintain accurate contact/esculation info (Annex C).
- Use Services per Acceptable Use Policy (no illegal, abusive, excessive automated traffic).
- Maintain backups of Customer data outside Provider systems (Provider not liable for Customer-deleted data).
- Comply with third-party platform terms (Shopify, Google, Meta, OpenAI, etc.).
- Report suspected security incidents immediately.
- Pay invoices per payment terms (Net 14).
10. Service Credits β General Terms
- Credits are sole and exclusive remedy for SLA breaches.
- Customer must request in writing within 15 business days of month-end.
- Credits applied as invoice offset (next billing cycle). Not refundable, not transferable.
- Max aggregate credits per month: 30% of monthly recurring fee.
- Credits not payable if breach caused by Customer, force majeure, or excluded events.
11. Term & Termination
- SLA term aligns with Service Agreement.
- Either Party may terminate SLA with 30 days' written notice for material breach uncured after 15 days.
- Provider may suspend Services for non-payment (>15 days overdue) with 5 days' notice.
- On termination: Provider assists transition (30 days, billable at T&M rates). Data returned per DPA.
12. Continuous Improvement & SLA Updates
- SLA reviewed at each QBR. Proposed changes documented, agreed in writing.
- Provider may improve targets unilaterally (e.g., 99.9% β 99.95%) with 30 days' notice.
- Degradation of targets requires Customer written consent.
- Change Control Process (Service Agreement) governs scope/architecture changes affecting SLA.
13. Limitation of Liability
- Provider's total liability for SLA breaches capped at service credits per Section 10.
- Neither Party liable for indirect, consequential, punitive, or special damages (lost profits, data, business opportunity).
- Provider not liable for: third-party platform actions, Customer code/content, force majeure, regulatory changes.
- Service Agreement limitation of liability clause applies to this SLA.
14. Force Majeure
Neither Party liable for failure/delay due to events beyond reasonable control: natural disasters, war, terrorism, civil unrest, government actions, pandemics, internet infrastructure failures, cloud provider outages, third-party platform changes, strikes. Affected Party notifies promptly; obligations suspended during event. If > 30 consecutive days, non-affected Party may terminate without liability.
15. Governing Law & Dispute Resolution
- Governing Law: Laws of the United Arab Emirates and Emirate of Dubai.
- Disputes: Good-faith negotiation (15 days) β Mediation (DIAC Mediation Rules) β Arbitration (DIAC Arbitration Rules, Dubai seat, English language, single arbitrator).
- If Customer is DIFC entity: DIFC Courts, DIFC Law.
- If Customer is ADGM entity: ADGM Courts, ADGM Regulations.
- Injunctive relief: Dubai Courts (or DIFC/ADGM Courts as applicable) for interim measures.
16. General
- Entire Agreement: Service Agreement + SLA + Annexes + DPA.
- Amendments: Written, signed by authorised representatives.
- Assignment: Neither Party without consent (not unreasonably withheld). Permitted: affiliate, successor, acquirer (with notice).
- Notices: Email to designated contacts + courier to registered addresses. Deemed received: email (on send), courier (on delivery).
- Waiver: No waiver unless written. Failure to enforce β waiver.
- Severability: Invalid provision severed; remainder enforceable.
- No Third-Party Beneficiaries: Except supervisory authorities (DPA).
- Language: English governing. Arabic translation for reference only.
SIGNATURES
CUSTOMER: [CUSTOMER LEGAL ENTITY NAME]
By: _______________________________
Name: _______________________________
Title: _______________________________
Date: _______________________________
PROVIDER: CYBERSPEED LLC
By: _______________________________
Name: _______________________________
Title: _______________________________
Date: _______________________________
ANNEX A β SERVICE DEFINITIONS
Complete per engagement. Defines scope, boundaries, and dependencies.
| Service Component | [e.g., Web App Hosting (K8s), SEO Platform Access, Shopify Store, AI API (RAG), Ad Dashboard, Expert Portal] |
|---|---|
| Environment(s) | [Production / Staging / Development / QA] |
| Hosting Region | [Azure UAE North / AWS ME-Central-1 / GCP Dubai] |
| Included Resources | [vCPU, RAM, Storage, Bandwidth, GPU, Requests/month β per tier] |
| Supported Integrations | [Shopify, Google Ads, Meta, OpenAI, Anthropic, Pinecone, SendGrid, etc.] |
| Backup Schedule | [Daily incremental, Weekly full, 30-day retention, Cross-region replication] |
| SSL/TLS | [Provider-managed (Let's Encrypt / ACM) / Customer-provided certs] |
| WAF Rules | [OWASP CRS + Custom rules per Customer request] |
| Monitoring Endpoints | [Health checks: /health, /ready, API endpoints, Synthetic transactions] |
| Access Methods | [SSH/VPN/SSO/GitOps β Customer responsibilities for credentials] |
| Excluded | [Customer application code, Customer data content, Third-party platform SLAs] |
ANNEX B β MONITORING & REPORTING SPECIFICATIONS
B.1 Monitoring Stack
- Infrastructure: CloudWatch / Azure Monitor / GCP Operations Suite + Datadog
- Application: Datadog APM / New Relic / OpenTelemetry
- Synthetic: Checkly / Pingdom (5-min intervals, 3 regions: Dubai, Frankfurt, Singapore)
- Logs: Centralised (Datadog Logs / Loki / CloudWatch Logs) β 90-day hot, 1-year cold
- Security: Cloudflare WAF logs, SIEM (Datadog Security / Sentinel)
B.2 Alerting Thresholds
| Metric | Warning | Critical | Notification Channel |
|---|---|---|---|
| CPU Utilisation | > 70% (5m) | > 85% (5m) | Slack #alerts, PagerDuty (P2) |
| Memory Utilisation | > 75% (5m) | > 90% (5m) | Slack #alerts, PagerDuty (P2) |
| Disk Usage | > 70% | > 85% | Slack #alerts, PagerDuty (P2) |
| API Error Rate (5xx) | > 0.5% (5m) | > 1% (5m) | PagerDuty (P1) |
| API Latency (p95) | > 2x baseline | > 4x baseline | Slack #alerts, PagerDuty (P2/P1) |
| SSL Cert Expiry | 30 days | 14 days | Email + Slack (P3/P2) |
| Backup Failure | Any | N/A | PagerDuty (P1) |
| Security Finding (Critical) | N/A | Any | PagerDuty (P1), Email to DPO |
B.3 Status Page
- Public:
status.cyberspeedllc.com(or Customer-branded) - Components: API, Database, Cache, CDN, AI Inference, Integrations
- Incident communication: Acknowledgment β€ 15 min (P1), Updates β€ 30 min (P1), Resolution post within 1 hr
ANNEX C β ESCALATION MATRIX
Complete with Customer contacts. Provider contacts listed below.
| Level | Role | Name | Phone | Availability | |
|---|---|---|---|---|---|
| Provider β P1 Critical | On-Call Engineer | [ENGINEER NAME] | oncall@cyberspeedllc.com | +971 50 XXX XXXX | 24/7 (rotation) |
| Engineering Lead | [LEAD NAME] | lead@cyberspeedllc.com | +971 50 XXX XXXX | 09:00β22:00 GST + on-call | |
| CTO | [CTO NAME] | cto@cyberspeedllc.com | +971 50 XXX XXXX | Escalation only | |
| Provider β P2 High | Team Lead | [TEAM LEAD] | teamlead@cyberspeedllc.com | +971 50 XXX XXXX | Business hours |
| Engineering Lead | [LEAD NAME] | lead@cyberspeedllc.com | +971 50 XXX XXXX | Business hours | |
| Provider β P3/P4 | Support Desk | Support Team | support@cyberspeedllc.com | +971 4 200 0000 | Business hours |
| Provider β Security | DPO / Security Lead | [DPO NAME] | dpo@cyberspeedllc.com | +971 50 XXX XXXX | 24/7 for breach |
| Customer β P1 Critical | Primary Contact | [NAME] | [EMAIL] | [PHONE] | 24/7 |
| Technical Lead | [NAME] | [EMAIL] | [PHONE] | Business hours + on-call | |
| Executive Sponsor | [NAME] | [EMAIL] | [PHONE] | Escalation only | |
| Customer β P2 High | Primary Contact | [NAME] | [EMAIL] | [PHONE] | Business hours |
| Technical Lead | [NAME] | [EMAIL] | [PHONE] | Business hours | |
| Customer β P3/P4 | Support Contact | [NAME] | [EMAIL] | [PHONE] | Business hours |
| Customer β Security | DPO / Security | [NAME] | [EMAIL] | [PHONE] | 24/7 for breach |
C.1 Escalation Paths
- P1: On-Call Eng β (15 min) Eng Lead β (30 min) CTO β (1 hr) Customer Primary β (2 hr) Customer Exec
- P2: Team Lead β (1 hr) Eng Lead β (4 hr) Customer Primary β (8 hr) Customer Tech Lead
- P3/P4: Support Desk β (SLA) Team Lead β Customer Primary
- Security Incident: DPO (Provider) β DPO (Customer) direct, parallel to P1 path. Legal/Compliance notified.
Contact for SLA Matters
CyberSpeed LLC β Service Delivery Manager
Email: sla@cyberspeedllc.com
Phone: +971 4 200 0000
Postal: FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE