(a) The Service Provider is responsible for the operation, availability, and performance of BlockchainCert under normal operating conditions, including application components and integrations within its direct control. The MasChain Network and third-party dependencies are subject to Appendix A.
(b) The Service Provider shall operate the Covered Services in accordance with applicable law and commercially reasonable, industry-aligned security practices, having regard to relevant OWASP guidance where applicable. Such reference does not represent certification or full adoption unless expressly stated.
The Service Provider’s responsibility includes:-
(a) operation of the BlockchainCert application, administration interfaces, Recipient portal, public verification portal, and Service Provider-controlled APIs;
(b) submission, processing, and handling of valid Credential, verification, portal, and API requests; and
(c) commercially reasonable security and resilience measures for the Covered Services within its control.
Notwithstanding any other provision, and notwithstanding Clause 12.1 of the Subscription Agreement, the Service Provider may proportionately suspend, restrict, modify, throttle, delay, or isolate access where it reasonably determines that action is necessary for legal, regulatory, security, fraud-prevention, Credential-integrity, operational-integrity, payment-risk, or platform-stability reasons, including:-
(a) compliance with applicable laws, regulations, regulatory directions, enforcement requests, sanctions, court orders or governmental requirements;
(b) the prevention, investigation or mitigation of suspected unlawful, fraudulent, abusive, unauthorised or non-compliant activity;
(c) preservation of the integrity, security, or stability of BlockchainCert, the MasChain Network integration, or related infrastructure;
(d) temporary suspension of transaction processing, throttling, rate limiting, isolation of affected components or emergency operational measures to prevent systemic risk, cascading failures or material service disruption;
(e) security incidents, malicious attacks, distributed denial-of-service attacks, coordinated attacks, zero-day exploits, or other vulnerabilities that exceed reasonable mitigation capacity despite appropriate security practices; and
(f) any Subscriber breach, fraudulent or unauthorised Credential activity, misuse, or abuse of the Covered Services.
Suspension for overdue payment remains governed by Clause 5.4 of the Subscription Agreement.
SLA commitments shall not apply to Unavailable Minutes, degradation, suspension, restriction, modification, throttling, delay, isolation, or another impact arising from any of the following events, circumstances, or actions, each an “Excluded Event”:-
(a) Subscriber Systems and Integration Issues: failures caused by Subscriber systems, browsers, devices, email access, networks, applications, data, credentials, configuration, or integrations;
(b) Third-Party Dependencies: failures of providers or services not under the Service Provider’s direct control, including email delivery, eGHL or another payment gateway, cloud, DNS, CDN, storage, the MasChain Network, or Subscriber-selected integrations, subject to Appendix A;
(c) Infrastructure and Hosting Limitation: failures of underlying cloud, hosting, data-centre, storage, or network infrastructure outside the Service Provider’s direct administrative control despite reasonable safeguards;
(d) Network Integrity and Stability Measures: actions taken by the Service Provider to preserve the integrity, security or stability of the platform, including temporary suspension of transaction processing, throttling, rate limiting, isolation of affected components and emergency operational measures to prevent systemic risk or cascading failures;
(e) Security Incidents and Malicious Attacks: Unavailable Minutes resulting from security incidents within reasonable and expected mitigation capabilities remain the Service Provider’s responsibility. SLA commitments do not apply to the portion caused by an incident that: (i) exceeds reasonable and proportionate mitigation capacity based on prevailing industry standards; (ii) involves a large-scale, coordinated, or state-level attack; or (iii) exploits a previously unknown vulnerability, including a zero-day exploit, where the Service Provider otherwise maintained appropriate security practices;
(f) Regulatory and Legal Compliance Actions: actions taken by the Service Provider in good faith where necessary to maintain compliance with applicable laws, regulations, regulatory directions, enforcement requests, sanctions, court orders or governmental requirements, including suspension, restriction or modification of the Services;
(g) Force Majeure: events beyond the Service Provider’s reasonable control, including natural disasters, acts of God, acts of war, terrorism, civil unrest, national emergencies, widespread power failures and large-scale telecommunications or internet outages;
(h) Subscriber Misuse or Breach: suspension or restriction resulting from breach of the Subscription Agreement, misuse or abuse of the Services, or unlawful, restricted or non-compliant activities by the Subscriber; and
(i) Blockchain Finality and Irreversibility: a verification record confirmed on the MasChain Network may be permanent and irreversible. The Service Provider does not guarantee reversal, amendment, recovery, or deletion of an on-chain hash, reference, NFT record, or transaction. A broadcast, callback, receipt, or confirmation is not a guarantee of legal validity, accreditation, employment, payment, or other business outcome. The Subscriber must validate Credential content, recipient details, permissions, and approvals before publication.
An impact arising from a valid Regulatory and Security Override or Excluded Event is excluded only to the extent reasonably attributable to that event and does not give rise to SLA Credits. The Service Provider shall use reasonable efforts to minimise the scope and duration, communicate material impact, restore normal service, and provide information reasonably required for the Subscriber’s lawful notifications where permitted.