3.1 This SLA defines the minimum operational standards for the production BlockchainCert platform, including credential issuance, credential management, recipient access, public verification, subscription and credit administration, notifications, reporting, and optional API or white-label functions expressly included in the Subscription Agreement.
3.2 This SLA applies only to the following production Covered Services to the extent they are enabled for the Subscriber and directly operated, managed, or controlled by the Service Provider:-
(a) organisation onboarding, profile administration, know-your-business (KYB) workflow, departments, staff roles, and access management;
(b) Credential template creation, design, preview, branding, and management;
(c) individual and bulk Credential creation, validation, PDF generation, publication, and delivery;
(d) blockchain anchoring of Credential verification records on the MasChain Network, including managed wallet and transaction handling performed by BlockchainCert;
(e) the organisation Credential management dashboard and lifecycle-status functions;
(f) the Recipient portal, including access, sharing, download, claim, and supported ownership-transfer workflows;
(g) the public verification portal, QR-code, reference-number, file-fingerprint, public-search, and microsite functions;
(h) subscription package, allocation, credit, top-up, invoice, and billing-administration functions;
(i) email notification and supported payment-gateway integration functions;
(j) API keys, documented API endpoints, callbacks, and webhooks, where included in the Subscription Package;
(k) platform reports, audit logs, localisation, and multilingual interface functions; and
(l) optional white-label, cloud, or on-premises deployment services only where expressly included in an Order Form or Statement of Work.
3.3 This SLA does not apply to any unavailability, degradation, delay, failure, loss, or interruption arising from or relating to:-
(a) Subscriber systems, applications, databases, networks, devices, browsers, access credentials, API integrations, or internal infrastructure;
(b) third-party email, telecommunications, internet, hosting, payment, identity, storage, DNS, CDN, or external API services not directly controlled by the Service Provider, subject to Appendix A;
(c) the MasChain Network or other distributed-ledger components outside the Service Provider’s direct operational control, subject to the responsibility and evidence standards in Appendix A;
(d) Subscriber-side configuration errors, inaccurate Credential content, misuse, unauthorised access, failure to follow Service Documentation, or failure to implement required updates or security measures;
(e) Scheduled Maintenance notified in accordance with Clause 6.1, Emergency Maintenance, or other exclusions expressly stated in this SLA;
(f) force majeure events, extraordinary cyberattacks, denial-of-service attacks, malware, regulatory intervention, or other events beyond the Service Provider’s reasonable control; or
(g) legal, regulatory, accreditation, employment, admission, licensing, commercial, financial, or other business outcomes arising from the Subscriber’s issuance or use of Credentials.
3.4 The Service Provider is responsible for the availability and performance of the Covered Services within its operational control. The Subscriber remains responsible for its Credential content, issuing authority, recipient notices and consents, users, access controls, compliance obligations, internal approvals, systems, integrations, and use of outputs generated through BlockchainCert.