
Standard Service Level Agreement (SLA) for Certain QMS
1. Purpose and scope
1.1 Purpose
This Service Level Agreement (SLA) governs Netpower Business Solutions AS’ delivery of Certain QMS (formerly Netpower Kvalitet) as a service. The agreement is intended to ensure high quality, stable operations, effective support, robust information security and predictability for the customer. The SLA sets out both Netpower’s obligations and the customer’s responsibilities, and forms part of our ISO 27001-certified information security management system (ISMS).
1.2 Scope
The agreement covers:
- Operation of the application in Netpower’s data centres, including monitoring and maintenance of the infrastructure.
- Maintenance, management and further development of the application itself, including source code, program fixes, security patching, updates and the release of new versions.
- User support, troubleshooting and fault correction in line with the defined criticality levels.
- Uptime guarantee and compensation arrangements.
- The process for handling support cases from registration through to closure.
- The option of an extended on-call line with round-the-clock cover.
- Specific provisions for custom functionality and for operation on the customer’s own infrastructure.
2. Definitions
- Uptime: the time during which the service is available from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in section 9 are not included.
- Response time: the time from a case being registered in Zendesk until troubleshooting has begun. The SLA guarantees the start of troubleshooting, not the time to resolution.
- Criticality levels: P1 (critical), P2 (high), P3 (medium), P4 (low); see section 6.
- ISMS: Netpower’s information security management system, certified to ISO 27001.
- Custom functionality: features or views developed specifically for one customer, which are not part of the standard version.
- Customer-operated infrastructure: cases where the application runs in the customer’s own environment or data centre rather than in Netpower’s data centres.
3. Operating environment and security
Netpower delivers operations from its own data centres in Stavanger, with a high level of physical and logical protection.
3.1 Physical and logical security
- Access control (personal card and code), security patrols, video and motion surveillance.
- Redundant power supply (UPS and diesel generator with automatic start).
- Redundant cooling and continuous climate control.
- Fire and humidity detectors, plus an Inergen fire suppression system.
3.2 Infrastructure and redundancy
- The option of High Availability (HA) with load balancing and failover configuration.
- Redundant network with at least two independent lines to the internet.
- Infrastructure designed for high availability and fast recovery in the event of a fault.
3.3 Server operations and patching
- All servers are operated with established routines for operating system and security patching.
- Critical updates and zero-day vulnerabilities are handled with accelerated patching outside the ordinary maintenance window where the risk warrants it.
- IDS/IPS rules, antivirus and anti-malware are updated continuously.
- Firewalls are configured on the principle of least privilege and are continuously updated with new signatures.
3.4 Monitoring and incident handling
- Servers, networks and services are monitored continuously, with automatic alarms for downtime, performance and security incidents.
- Incidents are handled according to established procedures in Netpower’s ISMS, including logging, analysis and escalation where required.
- Critical incidents are reported immediately and handled in accordance with the SLA.
All of these measures form part of Netpower’s ISO 27001-certified ISMS. The operating environment and security routines are audited annually and updated on an ongoing basis to meet new threats, vulnerabilities and regulatory requirements.
4. Support model, opening hours and channels
4.1 Support levels
- First-line service desk: receiving enquiries, triage, user support and simpler fault correction.
- Second line: application specialists and systems engineers with expertise in both the operating environment and the application.
- Third line: developers and architects with in-depth knowledge of the application architecture and code.
In addition to the ordinary support model, customers have access to comprehensive self-service resources:
- Help pages available at help.netpower-kvalitet.no, with up-to-date documentation and user guides.
- Training videos available through the help pages and often embedded directly in the customer’s own application.
- Contextual help in the application: from any module, the user can click the help icon (?) and be taken straight to the documentation relevant to that functionality.
During implementation and the project phase, the customer has direct access to the project team, including consultants and developers, and should not use the service desk for project-related questions in that period.
4.2 Opening hours and channels
The service desk is staffed on weekdays from 08:00 to 16:00. During these hours the support centre can be reached by telephone on 51 95 80 00, by email at support@certainqms.com or support@netpower.no, and through our online support system, either by creating a case or via live chat.
- The primary channel is Zendesk (our online support system).
- Email and telephone may also be used, but all incoming and outgoing enquiries are always logged in Zendesk.
- At times of heavy demand, the telephone queue is routed to additional staff to reduce waiting time.
5. Support case process
All support cases are handled through an established process in Netpower’s service desk. The process ensures that cases are assessed, prioritised and followed up predictably, and that the customer is always kept informed.
- The customer registers the case in Zendesk (the primary channel). Alternatively by email or telephone, in which case it is always logged in Zendesk.
- A ticket ID is created and the customer receives an automatic acknowledgement with the time and reference.
- All cases are monitored continuously by service desk staff throughout the day. Criticality (P1–P4) is assessed as soon as the case is registered.
- Troubleshooting is started by the first line. If the fault cannot be resolved there, the case is escalated to second or third line with the work carried out documented.
- P1 cases are escalated immediately and given the highest priority. Netpower deploys the most suitable resources straight away, including product owners and systems architects, so that the full breadth of expertise is mobilised quickly. Other tasks are set aside until the case is under control.
- Communication: all communication about a support case takes place in Netpower’s support system (Zendesk). This gives both the customer and Netpower a complete overview, history and traceability. For P1 cases the telephone may also be used for rapid clarification, but all updates and decisions are always logged in Zendesk.
- For larger customers, Netpower can arrange for the customer’s system owner to see and follow every case registered from the organisation. This gives an overview of status and progress, and helps ensure that any costs never come as a surprise.
- Once the case is resolved, closure is confirmed with the customer. Documentation and a description of the solution are provided where this is required or requested.
- Security-related P1 incidents are also handled as information security incidents in line with the ISMS procedure for incident handling, including notification, root cause analysis and corrective measures.
6. Criticality and response time (start of troubleshooting)
Response time is the time from the case being registered in Zendesk until troubleshooting has begun. The SLA guarantees the start of troubleshooting, not the time to resolution.
| Criticality | Ordinary SLA (08:00–16:00) | Extended SLA (optional on-call line) | Description and typical cases |
| P1 Critical | 1 hour | 30 min (24/7) | Total downtime or unavailability of the application. No users can log in or complete critical processes. Critical security incidents that threaten the confidentiality, integrity or availability of data. Examples: the entire system is down, the database is unavailable, a serious data breach. |
| P2 High | 2 hours | 1 hour (24/7) | Significant functionality is out of service for many users, but there is no total downtime. Workarounds exist, but business-critical processes are affected. Examples: non-conformity reporting is not working, major performance problems that prevent work, an integration with a critical third party is failing. |
| P3 Medium | 4 hours | 4 hours (08:00–22:00, including weekends) | Functionality is reduced or affects individual users, but core processes still work. Not business critical. Examples: a fault in a reporting function, limited performance problems, faults in individual modules that have a workaround. |
| P4 Low | 1 day | N/A | Cosmetic faults, user questions, minor faults or improvement requests that do not affect operations. Examples: an error in on-screen text, setting up a new user, a requested configuration change. |
Faults related to user synchronisation and access control
Certain QMS can be integrated with the customer’s identity environment (for example Azure AD or other AD solutions) using standards such as SCIM. In such cases, access problems may be caused by factors outside the application itself, for example changes in the customer’s identity register, synchronisation routines or configuration.
- Faults attributable to the customer’s identity environment are not treated as application faults under this SLA.
- Response time and criticality for such cases are assessed in dialogue between Netpower and the customer, and classified according to the actual cause and consequence.
- Netpower assists with troubleshooting and guidance to identify the cause, but operational responsibility for running and configuring the identity environment rests with the customer.
7. Uptime guarantee
Netpower guarantees 99.8% uptime per calendar month. Uptime is measured from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in section 9 are not included. Uptime measurement and the reporting of any shortfall form part of the ISMS and can be made available for audit.
8. Maintenance window
Primarily Wednesdays 23:59–05:59. Downtime in this interval is not automatic; Netpower works to keep any impact to a minimum.
9. Exceptions to uptime measurement
The following are not counted as a breach of the uptime guarantee:
- Downtime caused by the customer, or by faults in the customer’s equipment.
- Downtime at the customer’s request.
- Force majeure and natural disasters.
- Restarts, security updates and maintenance.
10. Compensation for SLA breaches
Netpower is committed to delivering the services in line with this SLA, and we take responsibility if the delivery does not meet the defined targets. To give the customer predictability and confidence, the following compensation arrangement is in place:
- If the uptime guarantee of 99.8% is not met in a calendar month, or
- If fewer than 90% of cases in the month are handled within the agreed response times,
… the customer will receive automatic compensation as a credit against the monthly fee.
Level of compensation:
- A 5% reduction in the monthly fee per breach.
- Total compensation per month is capped at 15% of the monthly fee.
Principles:
- The compensation is intended to reflect the reduced service quality and restore financial balance for the customer when targets are missed.
- The credit is applied to the following invoice, clearly specified as a separate line.
- Compensation is standardised and automatic, so the customer does not have to submit a separate claim.
- This arrangement is a minimum safeguard for the customer and applies in addition to the customer’s rights under the main agreement.
11. Backup and disaster recovery
- Netpower takes a daily backup of production data. Standard hosting includes 7 days’ retention before overwriting. The customer can order extended retention of up to 21 days at an additional cost.
- Recovery tests are carried out periodically and in accordance with the established routines in our ISO 27001-certified ISMS. Results are documented and assessed as part of the annual audit.
- Disaster recovery plans are established, documented and included in the ISMS. The plans are reviewed annually, and testing is carried out in line with the risk assessment and customer needs.
12. Change management and new versions
- Change requests are registered and estimated on an ongoing basis in dialogue with the customer.
- New versions and updates are made available to all licence customers.
- Upgrades are normally carried out in the agreed maintenance window and with regard to preserving customer-specific adaptations.
- The customer may choose to remain on an existing version for a limited period, but Netpower reserves the right to require an upgrade where this is necessary for reasons of security, stability, maintainability or regulatory compliance.
- Critical security updates and fault corrections are always distributed, and may be installed outside the maintenance window where necessary.
- Versions older than a defined life cycle (typically 12–18 months) will no longer be supported, and the customer is obliged to upgrade to a newer version. Netpower always gives advance notice of life cycles and support periods.
- Netpower makes sure customer-specific adaptations are preserved through upgrades, and helps the customer with any clarifications needed beforehand.
- Where critical vulnerabilities or security improvements are identified, Netpower reserves the right to upgrade or patch the application outside the maintenance window. This is done to safeguard information security and reduce the risk of service interruption or data loss. The customer is informed as quickly as possible before, during and after such an upgrade.
13. Custom functionality
For some customers, Certain QMS is delivered with custom functionality or tailored views developed specifically for that customer’s needs. Deliveries of this kind offer great flexibility, but they also carry particular considerations:
- Troubleshooting and fault correction: custom solutions may require more time to analyse and fix than standard functionality, since it may be necessary to involve the developers who know the specific adaptation.
- Upgrades: the risk of custom functionality being affected by an upgrade is higher than for the standard version. Netpower will do its best to preserve the adaptations, but cannot guarantee full compatibility with every new version. Any adjustments required are agreed with the customer.
- Response time: cases registered against custom functionality are handled in accordance with the SLA response times, but the time to resolution may vary more than for standard functionality. The customer is always kept informed of progress and the expected time to resolution.
- Maintenance: Netpower recommends that custom solutions are reviewed regularly together with the customer to ensure compatibility with new functionality and security updates.
Customisation gives customers added value, but it can mean that support, upgrades and fault correction require more time and coordination than for the standard solution.
14. Security, risk assessments and audits
- Netpower is ISO 27001 certified and has an established ISMS.
- Annual risk assessments are carried out of the application and the operating environment.
- The application is risk assessed at every main release.
- Certain QMS is penetration tested annually.
- Customers may on request receive copies of penetration test and risk assessment reports.
- External security audits are carried out regularly.
- Netpower assists customers with penetration and vulnerability testing and with audits.
15. Customer responsibilities and cooperation
The customer shall:
- Provide the access and information Netpower needs in order to deliver the service in accordance with the agreement.
- Ensure the quality of the data it enters into the system.
- Provide feedback without undue delay.
- Use the application for the purpose it was developed for, and in accordance with applicable laws, regulations and internal routines.
- Ensure that access control and user administration are managed on a need-to-know basis, and that unauthorised or unintended use of the system does not take place.
- Not use the application for purposes other than those agreed, or store information that is clearly unsuitable for the system (for example sensitive personal data, unless this has been agreed in writing).
Netpower is responsible for delivering a secure and stable solution in accordance with this SLA and the main agreement. The customer is responsible for how the solution is used internally, and for any consequences of incorrect use, inadequate access control or the storage of information beyond what the system is intended for.
16. Limitation of liability
Limitation of liability is governed by the main agreement between Netpower and the customer.
For the avoidance of doubt, Netpower cannot be held liable for faults caused by the customer’s own data, the customer’s systems or third-party deliveries.
17. Option: on-call line / extended SLA
For an additional fee, the customer can order an on-call line.
- Purpose: the on-call line exists to ensure that the application is available and that the operations services in Netpower’s data centre are working. The service applies only to incidents where the application or the server environment is unavailable (P1).
- Not included: the on-call line does not cover user support or the correction of functionality that can be handled within ordinary opening hours. Such cases must be registered in Zendesk and handled in accordance with this SLA.
- Availability: weekdays 16:00–22:00, weekends and public holidays 09:00–22:00.
- 24/7 option: for P1 incidents (a completely unavailable system), a 24/7 agreement can be entered into separately.
- Registration: Zendesk is always available 24/7/365 for registering cases.
18. Information security and ISO 27001
- All services covered by this SLA are delivered within Netpower’s information security management system (ISMS), which is certified to ISO/IEC 27001.
- The ISMS ensures a systematic approach to information security, including risk management, the establishment of security measures, ongoing monitoring and continuous improvement.
- Netpower carries out annual risk assessments of the application, the operating environment and the associated processes. The application is also risk assessed at every main release, to ensure that new versions do not introduce unacceptable risk.
- Certain QMS is penetration tested annually by external security partners. Results are assessed and followed up in line with the ISMS.
- Customers may on request receive a copy of the certificate, together with reports from risk assessments and penetration tests carried out, with due regard for confidentiality.
- Security incidents are handled through a defined process for information security incidents, including escalation, notification, root cause analysis and documented corrective measures.
- Netpower places corresponding requirements on its subcontractors, and supply chain security is followed up in accordance with ISO 27001 Annex A 5.19.
- Disaster recovery plans and contingency routines are established and reviewed annually.
- Continuous improvement of information security is part of the ISMS, and Netpower undertakes to keep pace with new threats, vulnerabilities and regulatory requirements.
19. Other provisions
Subcontractors, force majeure and dispute resolution follow the provisions of the main agreement.
20. Customer-operated infrastructure
For some customers, Certain QMS runs on the customer’s own infrastructure or in the customer’s internal data centre. In such cases the following specific provisions apply:
- Netpower is not responsible for the physical security, redundancy, power supply, cooling, monitoring or backup of the customer’s operating environment. These are the customer’s responsibility.
- Netpower depends on the customer providing the access needed to carry out updates, troubleshooting or other work. Response times under this SLA are counted from the point at which such access is given.
- Netpower cannot guarantee the same uptime or contingency cover as in Netpower’s own data centres, since this depends on the customer’s infrastructure and routines.
- The customer is obliged to ensure that the operating environment meets minimum requirements for security and performance, and that Netpower is given sufficient notice and access when needed.
This section applies only to customers where the application is operated on the customer’s own infrastructure or data centre.