Trust Centre
Service commitments
These are the current operating objectives for the early access service. They make our response priorities visible, but they are not an uptime SLA, warranty, service-credit program, or proof of disaster-recovery testing. A signed order form or MSA may set different terms.
Published: July 10, 2026
Service objectives
| Area | Current target | Important boundary |
|---|---|---|
| Availability | 99.5% monthly service availability objective | Planning objective only; not independently measured or backed by service credits |
| Recovery time (RTO) | Restore a materially unavailable core service within 24 hours | Operational target, not a tested or contractual disaster-recovery guarantee |
| Recovery point (RPO) | Limit loss after a recoverable infrastructure event to 24 hours of data | Operational target; customers must retain original records and regular exports |
| Planned maintenance | 48 hours advance email notice when maintenance is expected to cause material interruption | Emergency security or provider maintenance may occur without advance notice |
| Material product discontinuation | At least 30 days advance notice where reasonably practicable | Safety, legal, insolvency, or third-party events can shorten the period |
Support and escalation
Support is email-based and staffed on Canadian Atlantic business days. Acknowledgement means that the report has been received and triaged; it is not a resolution promise. There is no public 24/7 support channel today.
| Severity | Examples | Acknowledgement target | Update target |
|---|---|---|---|
| Critical | Broad service outage, confirmed account takeover, or suspected exposure of customer data | 4 business hours | Daily while active |
| High | A key workflow is unavailable with no reasonable workaround | 1 business day | As material progress occurs |
| Normal | How-to question, isolated defect, data request, or feature request | 2 business days | As appropriate |
Send urgent reports to hello@sredcopilot.ca with URGENT in the subject, affected organization, time first observed, impact, and a safe callback method. Do not email passwords, OAuth tokens, or unnecessary customer content.
Security incident notification
We target an initial notice without unreasonable delay and within 72 hours after validating that a security incident may have affected a customer's data. We will not wait for every forensic question to be resolved before notifying when the available facts support customer action. Applicable law or an executed agreement may require a shorter period and will control.
The initial notice should state what is known, affected data or systems, containment steps, recommended customer action, and the next update time. Later findings may correct the initial notice. A customer-specific 24/7 escalation or forensic-support obligation exists only in a signed agreement.
Continuity, export, and offboarding
- Keep your own archive. SR&ED Copilot is not the sole record repository for CRA, legal, or corporate-retention purposes.
- Export while active. Download project binders and generated documents after material review milestones; owners can also download a sanitized organization JSON export.
- Plan for integrations. Disconnect shows organization-wide provider evidence and citation impact, then requires the owner to keep or permanently purge the matching imported evidence.
- Post-termination window. The self-service Terms provide a 30-day period to request available data export after termination, subject to security, legal, and technical constraints.
- Deletion. Request account or imported-data deletion through the privacy contact. Primary-system and backup handling is described in the Privacy Policy; deletion is not instantaneous across provider backups.
What remains unverified or unavailable
- No independently audited uptime history or public status page
- No completed independent disaster-recovery or penetration-test report offered to customers
- No service-credit program for missed targets
- No default 24/7 phone or pager support
- No guaranteed Canadian-only deployment
If one of these is mandatory, do not rely on the operating target. Request a written term before onboarding.
See also the Trust Centre, Security & Data Handling, and Terms of Service.