Skip to main content

The Commitments Behind Every Stack9 Instance

Availability, recovery targets, support hours and severity-based response — April9’s standard commitments, quotable without a per-engagement caveat. Achieved performance is reported monthly; it is not asserted here as a historical track record.

Headline commitments

Four Numbers, Quoted Plainly

Standard commitments, underpinned by the architecture described in Security & Architecture.

Availability
99.90%
RPO
10 min
RTO
24 h
Warranty
90 days
Monthly availability, inclusive of scheduled maintenance. RPO and RTO apply from a client-declared ICT disaster. Warranty re-opens on every release, scoped to what that release introduced.
Support

Hours, Channels and KPIs

24/7 applies to ticket lodgement. Response and resolution run to the severity SLA within support hours, unless Premium Support applies for an agreed window.
ChannelHoursTarget response
Phone7am–5pm Qld time, weekdays80% of calls answered within 20 seconds
Email & web ticket7am–5pm Qld time, weekdays80% answered within 2 hours of creation
Support Portal (support.april9.au)24/7 for lodging and tracking ticketsOne ticket, one reference and one SLA clock, whichever channel it came from
Client's own ITSM toolAs per the client's own toolMeasured from logging in the client's system
Severity model

No Flat Fix-Time Promise — a Severity-Scaled One

Resolution targets are agreed per severity in the Service Management Plan; at least 80% of incidents are restored within the designated target for each level.
SeverityHow it is handledResponse targetResolution target
Critical & high severityTreated as incidents. The client sets the priority of each item at triage, so anything the client considers urgent is treated as urgent.Acknowledged and worked to the response target agreed for that priority level.Resolved to the agreed priority resolution time and released out of cycle where severity warrants.
Lower severityTriaged and prioritised with the client, who sets the priority at triage.Acknowledged and worked to the response target agreed for that priority level.Scheduled into the agreed release cadence, generally monthly, rather than forcing an unscheduled deployment.
Incident management

A Documented Process Under April9’s ISMS

1

Log & Classify

Every incident is logged in a central register and classified — availability, policy breach, data breach, security misconfiguration or operational.

2

Escalate Security Issues

Any incident with a security dimension escalates immediately to April9's Security Officer, regardless of its initial classification.

3

Communicate & Contain

Status is communicated at agreed intervals, with an interim workaround provided where a fix cannot land within the agreed time.

4

Find Root Cause

Root cause is determined using the 5 Whys method, with related systems scoped for the same exposure.

5

Report & Prevent

A P1 incident report follows within 5 working days: sequence of events, diagnosis, root cause and preventative action.

Releases

Governed the Same Way as Every Other Change

Every release, including low-code and AI Studio changes, is raised, reviewed and deployed under the Request for Change discipline described in Delivery.

Zero-Downtime By Design

ECS container hot-swap, automated schema migrations and automatic TLS renewal mean releases land without a maintenance window.

Severity-Scaled Defect Fixes

Critical and high-severity defects are resolved out of cycle; lower-severity defects go into the release cadence, generally monthly.

Notice, Not Surprises

60 business days' notice for upgrades, 15 days for planned maintenance, 7 days where disruption is unavoidable.

DR & backup ladder

From Continuous Recovery to an Annual Test

  • Point-in-time recovery. Near-continuous, log-based backup of the Aurora database — the mechanism behind the 10-minute RPO.
  • Daily RDS snapshots. Automated, running every day without manual intervention.
  • Monthly full database backups. A complete backup taken every month, alongside the daily snapshots.
  • Cross-region replication. Backups replicate to ap-southeast-4 (Melbourne), keeping the recovery position inside Australia.
  • Annual DR test. The Disaster Recovery Plan is tested every year against an approved test plan, with a DR Test Summary Report on completion.
  • Enhanced DR — optional, separately priced. A write-protected secondary backup with administrative separation, a six-month retention ladder and annual restoration testing, for clients needing protection against a compromised administrative account.
Reporting

Routine, Not on Request

Monthly Contract Report

Delivered within 7 working days of month end: SLA compliance, incident and change activity, and hosting cost against usage.

Quarterly Contract Meetings

Trending performance, contract compliance, service governance and KPIs, reviewed with the client at least every quarter.

Annual Performance Report

SLA compliance and contract performance for the financial year, delivered within two months of year end.

Ready to Put These Commitments in Writing?

Talk to us about your Service Management Plan, or see how these commitments carry through if you ever need to exit.