SERVICE LEVEL AGREEMENT

V2.10 (Last updated: 2026-06-01)

This Service Level Agreement (“SLA”) forms part of and is subject to the terms of the VaultN Terms and Conditions (“T&Cs”) published and amended from time to time by VaultN.

Any capitalized term not defined in this SLA has the meaning given to it in the T&Cs. Where a Service-specific Terms of Service contains provisions that conflict with this SLA, the Service-specific Terms of Service prevail in respect of that Service.


1. Interpretation Rules and Definitions

The following terms, used in this SLA, have the meanings set out below. All other capitalized terms have the meanings given in the T&Cs.

TermDefinition
Account Typeone of the following Account Types: Starter, Premium, or Enterprise. If Your Account Type is not specified in Your Plan, Your Account Type will be deemed “Starter.”
Availability (A)the time period during which material operational functionality of the applicable VaultN Platform, Service, or Add-On is available. Availability is calculated as set out in Section 2.
Availability Threshold (AT)the threshold of Availability applicable to Your Account Type, as set out in Section 4.
Business Daya day on which banks are operational, other than weekends, official public holidays, and religious holidays applicable in the Netherlands.
Business Hoursthe period between 9:00 AM and 5:00 PM Central European Time (CET/CEST) on any Business Day.
Compensationthe amount of compensation You may be eligible for under the compensation calculations in this SLA, to be applied as a credit against future Charges.
Critical Severitythe highest severity level of Defects, encompassing those that render the Platform inoperable or that cause a failure of order placement via API, order processing, or order fulfillment functionality, including but not limited to server crash and a material risk of imminent Platform unavailability.
Defectany malfunction of the Platform that materially deviates from the intended operation of the applicable VaultN Platform, Service, or Add-On.
Downtimethe time period during which the VaultN systems are materially inaccessible, excluding periods caused by Exceptions.
Exceptionsthe exceptions set out in Section 6.
Important Severitythe third severity level of Defects: those that do not render the Platform inoperable, have no direct adverse impact on order placement, processing, or fulfillment, but affect non-transactional functionality, including UI access to core workflows, key management, reporting, or dashboard access, or have the potential to affect order-critical functions if left unaddressed.
Long-Term Resolutiona permanent or longer-term solution requiring an adjustment to the Platform to ensure that no further Availability impacts arise from the Defect.
Resolution Timethe time period in Business Hours within which a Defect will be resolved, commencing after the Response Time has elapsed. Resolution Time varies based on the Severity Level as set out in Section 3.
Response Timethe time period in Business Hours within which a response will be provided to the relevant support request for a Defect.
Service Level Objectives (SLO)non-binding objectives for service levels for which VaultN will use reasonable resources.
Severity Levelthe Severity Level applicable to a Defect as categorized in Section 3.
Short-Term Resolutiona hot fix: a temporary solution to a Defect or a workaround aimed at re-establishing Availability.
Urgent Severitythe second highest severity level of Defects: those that do not meet the Critical Severity threshold but cause a failure of order-adjacent API functionality, including key delivery, Key on Demand / Just-in-Time retrieval, webhooks, or reservations, where order placement and processing remain operational but active fulfillment or downstream automation is materially affected. Key upload failures default to Important Severity and may be escalated to Urgent Severity where VaultN determines the failure affects a title with active fulfillment obligations and no available key inventory.

2. KPIs and Metrics

2.1 This Section sets out the key performance indicators and metrics used to calculate Availability and Compensation under this SLA.

2.2 Availability is the complement of Downtime. Downtime is reduced for any period caused by an Exception: A = 1 − DF.

2.3 Downtime Fraction is the proportion of the total quarterly period during which the VaultN Platform, Service, or Add-On was materially inaccessible. DF = Total Downtime (hours) / Total Available Hours in the Quarter.

2.4 Normalized Downtime Factor (NDF) is the measurement that normalizes the Downtime Fraction relative to the applicable Availability Threshold (AT), producing a value between 0 and 1. NDF = (DF − AT) / 0.05.

2.5 AT is the applicable Availability Threshold expressed as a downtime fraction (e.g. 0.01 for a 99% threshold; 0.001 for a 99.9% threshold). The denominator 0.05 represents the fixed width of the compensation band.

2.6 The average of the monthly Charges paid to VaultN (AMC) for the affected Services or Add-Ons during the quarter preceding the occurrence of the Defect. AMC = Total Charges paid for the affected Services or Add-Ons during the preceding quarter / 3.

2.7 The maximum Compensation (MC) payable under this SLA. MC = 0.25 × AMC.


3. Severity Levels and Response Times

The following response and resolution times apply based on Severity Level and Account Type. All times are in Business Hours. Availability measurements apply continuously; support response and resolution times are measured during Business Hours unless expressly agreed otherwise in a Plan.

Severity LevelAccount TypeResponse TimeShort-Term ResolutionLong-Term Resolution
Critical SeverityStarter8424
Premium4416
Enterprise248
Urgent SeverityStarter16848
Premium8824
Enterprise4816
Important SeverityStarter242472
Premium162448
Enterprise82424
OtherAll Account Types48No fixed Resolution Time (see 3.1)—

Resolution Time is measured after the Response Time has elapsed. All values are in Business Hours.

3.1 Other Severity applies to all Account Types. No fixed Resolution Time applies; Defects are addressed in accordance with VaultN’s development roadmap.


4. Service Levels and Objectives

4.1 Certain Service Level Indicators and/or Service Level Objectives may only be applicable to specific Services and Add-Ons, as specified below or indicated on the VaultN Platform.

4.2 Whether Service Level Objectives (SLO) or Service Level Agreement (SLA) provisions apply depends on the Account Type as defined under the applicable Plan. VaultN reserves the right to offer differentiated service levels and response times according to the designated Account Type as follows:

  • SLO: Starter
  • SLA: Premium, Enterprise

4.3 UI-only disruptions are generally of lower severity than API disruptions. The functional tier classification set out in Sections 4.4 to 4.9 applies for the purposes of Severity Level assessment.

4.4 Critical Severity applies to Defects that render the Platform inoperable or that cause a failure of any of the following: (a) order placement via API; (b) order processing; or (c) order fulfillment functionality, including but not limited to server crash and a material risk of imminent Platform unavailability. For the purposes of this Section, the Platform is inoperable if the core API and UI are both materially inaccessible for all users of the Account.

4.5 Urgent Severity applies to Defects that do not meet the Critical Severity threshold but cause a failure of order-adjacent API functionality, including: (a) key delivery; (b) Key on Demand / Just-in-Time (KOD/JIT) retrieval; (c) webhooks; and (d) reservations, where order placement and processing remain operational but active fulfillment or downstream automation is materially affected.

4.6 Important Severity applies to Defects affecting non-transactional functionality, including: (i) UI access to core workflows; (ii) key management UI and key upload in normal conditions; (iii) reporting and analytics; and (iv) dashboard access.

4.7 VaultN retains discretion to classify a Defect at Important Severity or below based on actual impact, and to escalate any Defect to a higher Severity Level where it determines the failure has a material adverse impact on order-critical functions.

4.8 Key upload failures default to Important Severity. Where VaultN determines that a key upload failure affects a title with active fulfillment obligations and no available key inventory, the classification may be escalated to Urgent Severity.

4.9 Other Severity applies to cosmetic defects, minor display issues, and non-operational features with no impact on order processing, fulfillment, or core workflow access.

4.10 Collection Services and wallet transactions processed via the Payment Service Provider are governed exclusively by the Collection Terms of Service and are excluded from the Availability calculations and Severity classifications under this SLA.

4.11 The following Availability Thresholds apply for purposes of the Compensation framework under this SLA:

  • Starter: SLO of 99%
  • Premium: SLA of 99%
  • Enterprise: SLA of 99.9%

4.12 Compensation for Downtime applies only if Availability for the respective Account Type falls below these thresholds, calculated as set out in Section 2.

4.13 Availability Thresholds are measured against total available hours in the quarter, excluding any periods of unavailability caused by Exceptions as defined in Section 6.


5. Compensation Calculation

5.1 Any Compensation under this SLA will be applied as a credit against future Charges.

5.2 For Services and Add-Ons, Compensation applies only if Availability falls below the Availability Threshold. Compensation is limited to the Services or Add-Ons affected by the Downtime.

5.3 No Compensation is due for an SLO.

Other than the Exceptions, the following Compensation method applies for Downtime caused by failure to resolve any Defect after the relevant Resolution Times set out in Section 3 have elapsed.

Availability (A)*Compensation TierCompensation
A ≥ AT10
A < AT2MC × NDF

* Calculated after the relevant Resolution Times have elapsed.

5.4 The following example illustrates the Compensation calculation using the metrics defined in Section 2. The values used are illustrative only.

Assumed values: Account Type: Premium; AT = 99% (0.01 as a downtime fraction); A = 97% (0.97); AMC = $500.

  • Step 1 — Downtime Fraction (DF): DF = 1 − A = 1 − 0.97 = 0.03
  • Step 2 — Normalized Downtime Factor (NDF): NDF = (DF − AT) / 0.05 = (0.03 − 0.01) / 0.05 = 0.4
  • Step 3 — Maximum Compensation (MC): MC = 0.25 × AMC = 0.25 × $500 = $125
  • Step 4 — Compensation Tier: A = 97%, which is below AT (99%), so Tier 2 applies.
  • Step 5 — Compensation: MC × NDF = $125 × 0.4 = $50

Result: for 97% Availability and an AMC of $500, Compensation is $50.

5.5 To claim Compensation, You must submit a written request to VaultN via the support channels set out in Section 7.2 within 30 days of the end of the quarter in which the relevant Downtime occurred. Claims submitted after this period will not be eligible for Compensation.

5.6 VaultN may notify You if Availability for a quarter falls below the applicable Threshold. Any Compensation remains subject to a valid claim submitted in accordance with Section 5.5.

5.7 VaultN will review and respond to a Compensation claim within 30 Business Days of receipt. Where VaultN accepts a claim, the applicable Compensation credit will be applied to Your next invoice.

5.8 Any dispute regarding a Compensation claim that cannot be resolved between the parties will be subject to the governing law and jurisdiction set out in Section 9.


6. Exceptions

6.1 The following are Exceptions to the undertakings under this SLA:

  1. You have unpaid Charges due and invoiced, or no Services or Add-Ons are activated in Your Account.
  2. Defects caused by the hardware through which the VaultN Platform, Services, and Add-Ons are accessed, the operating software installed on that hardware, or incompatibility of the VaultN Platform, Services, and Add-Ons with any hardware or software used by You, any Main User, or any Other User; or by use of third-party software, whether authorized or not, except where VaultN has approved such software in writing.
  3. Defects caused by actions or inactions by You, any Main User, Other Users, or Your employees, agents, contractors, or vendors, or anyone gaining access to the VaultN Platform, Services, or Add-Ons using Your passwords or equipment, that are not in accordance with the T&Cs; by abuse or other conduct that violates this SLA, the T&Cs, Terms of Service, or other applicable terms; or by Your continued use after VaultN has instructed You to change Your usage and You have not done so.
  4. Defects, degradation, latency, or unavailability caused by errors in Your API integration, including misconfigured requests, incorrect authentication credentials, or failure to implement notified API updates; by abnormal or excessive API request volumes exceeding documented rate limits; by Your use of deprecated API versions where VaultN has given at least 90 days’ prior notice and made commercially reasonable efforts to provide a migration path; or by Your enrollment in or use of beta, trial, early access, preview, experimental, or demo features.
  5. Inability to access the VaultN Platform, Services, Add-Ons, or support channels caused by Your Account not meeting the minimum required security settings published in VaultN’s documentation from time to time, including failure to implement security measures made available or recommended by VaultN, such as Multi-Factor Authentication.
  6. Defects caused by Force Majeure events; by third-party service providers beyond VaultN’s control, such as electricity and remote server outages; by distributed denial-of-service attacks, cyberattacks, or other malicious third-party actions directed at VaultN’s infrastructure, provided VaultN has implemented security measures in accordance with VaultN’s applicable information security policies and procedures; by internet infrastructure failures outside VaultN’s network perimeter, including DNS resolution failures, CDN outages, or routing failures not within VaultN’s control; or by outages or failures of third-party communication providers, including email providers or collaboration platforms.
  7. Defects caused by the Payment Service Provider, including failures of payment processing, wallet transactions, or any other functionality operated by the Payment Service Provider under the Collection Terms of Service, which are governed exclusively by those terms.
  8. Unavailability resulting from VaultN’s compliance with Applicable Law, including any regulatory direction, court order, or sanctions obligation requiring VaultN to restrict or suspend access.
  9. Defects within environments other than the VaultN Platform, Services, or Add-Ons, such as staging, testing, or sandbox environments.
  10. Maintenance windows as notified in accordance with Section 7.1.

6.2 The Exceptions above represent circumstances in which the SLA undertakings do not apply. If the VaultN Platform, Services, or Add-Ons become inaccessible or unavailable due to an Exception, no Availability undertaking applies for the duration of that Exception.

6.3 VaultN may temporarily suspend access to the VaultN Platform, Services, or Add-Ons where reasonably necessary to protect platform integrity, security, stability, or availability, or to comply with Applicable Law. Such suspension will be notified as soon as practicable and constitutes an Exception for the duration of the suspension.


7. Maintenance and Support Services

7.1 VaultN will perform the following categories of maintenance on the VaultN Platform, Services, and Add-Ons:

  1. Routine maintenance: VaultN will perform routine maintenance on the VaultN Platform, Services, and Add-Ons. VaultN will perform routine maintenance periodically as needed.
  2. Scheduled maintenance: VaultN may carry out scheduled maintenance as necessary. Scheduled maintenance dates will be posted on the VaultN Platform at least 7 (seven) days prior. VaultN will use commercially reasonable efforts to schedule planned maintenance outside peak operational periods. This is an objective, not an obligation.
  3. Extraordinary or emergency maintenance: VaultN may carry out maintenance where reasonably required to protect the security, integrity, availability, or stability of the VaultN Platform, Services, or Add-Ons, including in response to Defects, vulnerabilities, attacks, abuse, infrastructure failures, or third-party service disruptions. The timing and expected duration will be notified to You as soon as practicable.
  4. Maintenance windows notified in accordance with this Section constitute an Exception under Section 6 and do not give rise to Compensation under Section 5.

7.2 VaultN provides support via email, online form, Microsoft Teams Channel, and on-site support, depending on the applicable Account Type. Support requests should be submitted by email to [email protected] or via the online form at: https://www.vaultn.com/contact-us/.

7.3 Support services provided depend on the applicable Account Type as follows:

  • Starter: Email and Online Form support only.
  • Premium: Email, Online Form, and Microsoft Teams Channel.
  • Enterprise: All of the above, with priority routing and optional on-site support.

7.4 VaultN will use commercially reasonable efforts to acknowledge support requests within the following target periods: Critical Severity: 1 Business Hour; Urgent Severity: 1 Business Hour; Important Severity: 4 Business Hours; Other: 1 Business Day. Acknowledgement confirms receipt and initiates the assessment and classification process. VaultN retains sole discretion regarding Severity Level classification in accordance with Section 4.

7.5 For Enterprise Accounts, if a Critical Severity Defect remains unresolved after the Short-Term Resolution Time has elapsed, You may request escalation by contacting VaultN via Your designated Microsoft Teams Channel. VaultN will use commercially reasonable efforts to provide a named escalation contact within 2 Business Hours of such request.

7.6 VaultN will use commercially reasonable efforts to notify You of any Critical Severity or Urgent Severity Defect within 2 Business Hours after confirmation by VaultN, either via the VaultN Platform or by email to Your registered Account address. VaultN will use commercially reasonable efforts to confirm the start and end time of any Downtime event in the relevant notification or a follow-up communication.

7.7 During Critical Severity incidents, VaultN will use commercially reasonable efforts, where reasonably practicable, to provide periodic status updates via the VaultN Platform or by email.

7.8 A security incident affecting the Platform does not automatically constitute an Availability failure unless and to the extent it materially impacts the operational availability of the affected Services for purposes of this SLA. VaultN will notify You in accordance with this Section where the incident materially impacts Availability. Notification does not constitute acknowledgment of a Compensation entitlement.

7.9 In special circumstances where remote support is not sufficient to detect and resolve a Defect, VaultN may provide on-site support, provided that the costs of such on-site support are covered by You separately. You will fully cooperate and ensure that VaultN-authorized representatives have access to all facilities reasonably necessary to provide such support and resolve the Defect.


8. Representations and Indemnification

8.1 The VaultN Platform, Services, and Add-Ons may be accessed via UI, API, or both, as applicable. VaultN will maintain commercially reasonable measurement and monitoring tools and procedures to monitor performance against the applicable service levels and will notify You of any issue likely to materially affect the provision of the VaultN Platform, Services, or Add-Ons, either on the VaultN Platform or by separate email notification. Availability is measured by VaultN’s internal monitoring systems on a quarterly basis, and VaultN’s measurement records shall be conclusive absent manifest error.

8.2 You agree to indemnify and hold harmless VaultN, including its subsidiaries, affiliates, and all their officers and employees, from any losses, damages, or claims made by third parties. This includes covering reasonable attorney fees and costs. The claims may arise from (i) a breach of the above representations; (ii) Your participation in Prohibited Activities on the VaultN Platform, Services or Add-Ons, (iii) Your violation of others’ rights, like intellectual property, or (iv) Your use of the VaultN Platform, Services or Add-Ons in a harmful manner. VaultN may take over the defense of any situation requiring Your protection, and You must assist at Your own cost. VaultN will inform You about any related claims, actions, or proceedings without undue delay. VaultN reserves the right to take appropriate legal action, including without limitation pursuing civil, criminal, and injunctive redress.


9. Miscellaneous

9.1 This SLA is governed by the laws of the Netherlands. Any disputes arising under or in connection with this SLA are subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands.

9.2 This SLA enters into force on the Effective Date and remains in force until the termination of the T&Cs.

9.3 Notices under this SLA will be given, and this SLA may be amended by VaultN, in accordance with Section 12 of the T&Cs.

9.4 The Compensation mechanism in Section 5 constitutes Your sole remedy for Availability failures under this SLA, except to the extent liability cannot be excluded or limited under Applicable Law or the T&Cs.

9.5 All liability arising under or in connection with this SLA remains subject to the exclusions and limitations of liability set out in the T&Cs.

9.6 VaultN remains responsible for the provision of the applicable service levels under this SLA regardless of whether services are delivered through subcontractors, subject to the Exceptions in Section 6.

9.7 Upon written request, VaultN will provide You with availability records for the relevant quarter within 10 Business Days of receipt of such request. VaultN will retain availability records for a minimum of 12 months.

9.8 In the event of any conflict between this SLA and the T&Cs, the T&Cs prevail unless this SLA expressly states otherwise.

9.9 The general provisions of the T&Cs, including those relating to entire agreement, no waiver, severability, and assignment, apply to this SLA.

9.10 Any Compensation claims accrued prior to termination of the T&Cs remain payable in accordance with Section 5.