Legal
Service Level Agreement
Vera · Marco · Lilly · Atlas
Effective Date: the Effective Date of the Master Services Agreement (the “MSA”) between Pennix, Inc. (“Pennix”) and Customer.
Contents
01Scope
1.1 This SLA applies to the production Pennix Service at live.pennix.ai and the production API at api.pennix.ai, accessed by Customer at a subscription tier of Firm or higher with an active, paid subscription and current account in good standing.
02Definitions
2.1 “Monthly Uptime Percentage” means, for any calendar month, the total number of minutes in the month minus the number of minutes of Downtime, divided by the total number of minutes in the month, expressed as a percentage.
2.2 “Downtime” means any continuous period of one or more minutes during which the Production Service (as defined in §3) is Unavailable, as measured by Pennix’s external synthetic monitoring (see §4), and excluding any period covered by §6 (Exclusions).
2.3 “Unavailable” means: (a) for the SPA at live.pennix.ai: the production CloudFront distribution returns a 5xx error or fails to load for more than two consecutive synthetic checks (≥ 60 seconds); (b) for the API at api.pennix.ai: HTTPS requests to the API health endpoint (/health) return a 5xx error rate exceeding 50% over two consecutive 60-second windows; (c) for Workflow processing: new Step Function executions cannot be started, or executions cannot transition through normal states for more than 15 minutes.
2.4 “Service Credit” means a credit, expressed as a percentage of the monthly subscription fee for the affected subscription tier, that Pennix applies against Customer’s next monthly invoice.
2.5 “Production Service” has the meaning in §3.
2.6 “Scheduled Maintenance” means maintenance for which Pennix has given Customer at least 5 business days’ prior notice via in-product banner or email, and which is conducted outside U.S. business hours (i.e., between 6:00 PM and 6:00 AM Pacific Time, Monday–Friday, or on weekends or federal holidays).
2.7 “Emergency Maintenance” means maintenance Pennix performs on shorter notice to address a security vulnerability, a stability issue, or a third-party-imposed urgent change. Pennix will give Customer as much notice as commercially reasonable.
03Production Service components
The Production Service consists of:
| Component | Endpoint(s) |
|---|---|
| SPA (web app) | live.pennix.ai |
| API | api.pennix.ai |
Component-specific behavior:
- SPA: the page must load and the OAuth flow must complete.
- API: REST endpoints must return non-5xx responses; authentication must succeed for users with valid credentials.
- Workflow: new intakes must start within 60 seconds of submission; classification map states must execute (subject to Anthropic rate-limit dependency under §6.5).
- Inbound email: emails delivered to a Customer’s agent address must result in an intake record within 5 minutes of Postmark delivery to Pennix.
04Measurement
4.1 Pennix measures availability using external synthetic monitoring that runs from at least three U.S. AWS regions on a 60-second cadence. The monitoring scripts and last-30-days raw availability data are published at pennix.ai/trust/availability.
4.2 Pennix’s measurement is the authoritative source for SLA calculations. If Customer disputes Pennix’s measurement, Customer may submit independent monitoring data (with timestamps, request IDs, and source IP) within the claim window in §5.5; Pennix will review and reconcile in good faith.
05Service-level commitment and credits
5.1 Uptime target
Pennix targets 99.9% Monthly Uptime Percentage for the Production Service (“Service Level”), measured per calendar month.
5.2 Service Credit schedule
If the Monthly Uptime Percentage falls below 99.9% in any calendar month, Customer is eligible for the following Service Credit, calculated as a percentage of the monthly subscription fee for the affected month:
| Monthly Uptime Percentage | Service Credit |
|---|---|
| < 99.9% and ≥ 99.0% | 0% |
| < 99.0% and ≥ 95.0% | 10% |
| < 95.0% | 25% |
5.3 Cap on Service Credits
Service Credits in any calendar month will not exceed 25% of that month’s subscription fee for the affected tier. Service Credits are non-cumulative across months in the sense that an outage in one month does not entitle Customer to credits in another month.
5.4 Form of credit
Service Credits are applied against the next invoice and have no cash value. Service Credits are forfeited on termination of the MSA for cause by Pennix under MSA §5.3, or on termination by Customer not for Pennix’s material breach.
5.5 How to claim
To receive a Service Credit, Customer must submit a written claim to service@pennix.ai within 30 days after the end of the calendar month in which the Downtime occurred, including (a) the affected subscription tier and Customer tenant ID, (b) the dates and times of the alleged Downtime, (c) the affected components, and (d) any monitoring or log data supporting the claim. Pennix will respond within 15 business days, applying credit where due or providing the basis for denial. Failure to submit a timely claim waives the right to the Service Credit.
5.6 Sole remedy
The Service Credits set out in this §5 are Customer’s sole and exclusive remedy, and Pennix’s entire liability, for any failure of the Service to meet the Service Level.
06Exclusions
The following are excluded from Downtime calculations:
6.1 Scheduled Maintenance. Pennix will cap Scheduled Maintenance at 4 hours per calendar month.
6.2 Emergency Maintenance, capped at 2 hours per calendar month in the aggregate. (Pennix targets zero emergency maintenance during U.S. business hours; targeting is best-efforts.)
6.3 Customer-caused issues, including but not limited to: misconfiguration by Customer, denial-of-service traffic originating from Customer’s account, abuse of API rate limits, use of unsupported integrations, or breach of the MSA.
6.4 Force-majeure events as defined in MSA §18.3.
6.5 Third-party dependencies outside Pennix’s control, including outages of AWS regions or services, Anthropic API outages or rate-limit constraints, Stripe outages affecting billing or checkout, Postmark outages affecting email send / inbound, DNS provider outages, or ISP outages affecting Customer or end users. If the dependency is partial (e.g., Anthropic rate-limiting), Pennix will surface the impact via the status page and may degrade specific AI Agent functionality (e.g., classification falls back to slower processing) without that being treated as Downtime, provided Customer can still submit intakes and view existing data.
6.6 Suspension under MSA §4.3 or §5.3. Downtime caused by suspension for non-payment or material breach is not counted.
6.7 Beta, preview, or pilot features, even if otherwise reachable via the production endpoints.
6.8 Pennix Desktop Helper sessions, which are addressed by §7.
07Pennix Desktop Helper service objective
7.1 The Pennix Desktop Helper provides RPA integration with desktop tax-prep platforms (e.g., Drake, ProSeries, UltraTax) through ephemeral Windows VMs.
7.2 Pennix targets, as a service objective only (not an SLA), a Helper-session provisioning time of < 90 seconds from request to ready, and a recipe-completion success rate of ≥ 95% for supported workflows in supported platform versions, measured on a rolling 30-day basis. Failure to meet this objective does not entitle Customer to a Service Credit.
7.3 If a Helper session terminates mid-recipe (e.g., due to the 60-minute idle terminator, VM crash, or platform change in Drake/ProSeries/UltraTax), the in-flight recipe is abandoned and Customer is notified in-product. No automatic retry is attempted for irreversible actions.
7.4 The Desktop Helper depends on third-party platform vendor terms of service. If a vendor changes its terms or technically blocks automation, Pennix will give as much notice as commercially reasonable and may modify or withdraw the Helper for the affected platform.
08Solo tier
Customers on the Solo subscription tier are not entitled to the Service Credits in §5. For Solo customers, Pennix targets the same 99.9% availability as a best-efforts objective, publishes the same status data, but does not offer financial remedy for missed targets. Solo customers retain all other rights under the MSA, including the right to terminate for material, uncured breach.
09Support
9.1 Hours
- Tax season (January 1 – April 30, U.S.): support is staffed 7 days/week, 8 AM – 8 PM Pacific Time.
- Off-season (May 1 – December 31): support is staffed Monday–Friday, 9 AM – 5 PM Pacific Time, excluding U.S. federal holidays.
9.2 Severity definitions and response targets
Response time is the time from Pennix’s receipt of a properly submitted ticket to first substantive Pennix response (not auto-acknowledgment).
| Severity | Definition | Response time target (in season) | Response time target (off season) |
|---|---|---|---|
| Sev-1 | Production Service is Unavailable; or a confirmed security incident affecting Customer Data; or a confirmed data-isolation breach. | 1 hour | 8 hours |
| Sev-2 | A core feature is materially degraded for most of Customer’s users; no usable workaround. | 8 hours | 1 business day |
| Sev-3 | A non-core feature is impaired, or a feature is impaired but a workaround exists. | 1 business day | 2 business days |
| Sev-4 | Cosmetic issue, feature request, documentation question. | 3 business days | 5 business days |
9.3 Founding-firm support
For Customers designated as founding firms in their Order, Pennix also provides:
- Same-business-day response targets in tax season (improving on the Sev-2/Sev-3 table above).
9.4 Escalation
Customer may escalate by replying to the existing ticket and adding [ESCALATE] to the subject line, which routes the ticket to engineering on-call. Repeated unwarranted escalation may be denied.
9.5 Channels
- Primary: service@pennix.ai
- Status page: pennix.ai/status (subscribe for email or webhook alerts)
- Security incidents: service@pennix.ai and (for confirmed incidents) the contact in MSA §7.7
10Disaster recovery and data protection objectives
Pennix maintains the following objectives, which are operational targets supporting MSA §7 (Security) and the Service Level above. They are not separately credit-bearing; missed objectives may, however, materially contribute to Downtime.
| Metric | Target |
|---|---|
| Recovery Point Objective (RPO) | 2 hour2 |
| Recovery Time Objective (RTO) | 4 hours |
| Backup retention (DDB PITR) | 35 days |
| Audit log retention (S3 Object Lock, compliance mode) | 7 years |
| Cross-region replication lag (production data) | < 15 minutes |
| DR drill cadence | Quarterly |
| Annual full failover drill | Once per year |
11Security incident response timing
11.1 In addition to the 72-hour notification commitment in MSA §7.7, Pennix targets the following incident-handling timelines:
| Phase | Target |
|---|---|
| Detect → triage (during business hours) | 1 hour |
| Detect → triage (outside business hours, tax season) | 2 hours |
| Triage → containment | 4 hours |
| Containment → root-cause identification | 5 business days |
| Customer-facing post-mortem | 15 business days |
11.2 These targets are objectives, not SLAs. They do not entitle Customer to Service Credits.
12Changes to this SLA
Pennix may modify this SLA in accordance with MSA §17. Pennix will not reduce the Service Level below 99.9%, or the credit percentages below those set out in §5.2, without offering existing Customers under an active Subscription Term the right to terminate the affected Order without penalty.
13Contact
Service-credit claims: service@pennix.ai
Security incidents: service@pennix.ai
Legal and contract matters: service@pennix.ai
Status page: pennix.ai/status