Service Level Agreement

Effective date: October 2026 ยท Version 1.0

This SLA covers the availability, performance, support and security commitments for Yona's e-invoicing platform: creating and managing invoices, submitting them to the Nigeria Revenue Service (NRS), webhook event delivery, billing, and the sandbox environment for testing.

This SLA applies to the production environment only. Sandbox environments are provided on a best-effort basis.

1. Service Availability

1.1 Uptime Commitment

MetricTarget
Monthly uptime99.9%
Maximum scheduled downtime per month45 minutes
Scheduled maintenance windowSundays 02:00โ€“04:00 WAT (with 48-hour advance notice)

Uptime is measured as the percentage of minutes in a calendar month during which the API Gateway returns successful health check responses, excluding scheduled maintenance.

1.2 Uptime Calculation

Uptime % = ((Total minutes in month โˆ’ Downtime minutes) / Total minutes in month) ร— 100

2. Performance

2.1 API Response Times

MetricTarget
P50 (median) response time< 200ms
P95 response time< 500ms
P99 response time< 1,500ms

Measured at Yona's API for standard operations (creating, reading and listing invoices). Excludes time spent inside the NRS systems, which Yona does not control.

2.2 Webhook Delivery

MetricTarget
First delivery attemptWithin 30 seconds of event
Retry policyExponential backoff, up to 5 retries over 24 hours
Delivery success rate (recipient reachable)> 99%

2.3 Submission Processing

MetricTarget
Invoice creation to first transmission attempt to NRS< 10 seconds (NRS processing time excluded)

3. Support

3.1 Support Channels

ChannelAvailability
Email support (support@elyonar.ng)24 hours a day, 7 days a week
Critical incidents (P1), by email marked URGENT24/7, acknowledged within the P1 response time
API status page24/7 (automated)

3.2 Incident Severity and Response Times

PriorityDefinitionResponse TimeResolution Target
P1 โ€” CriticalService completely unavailable; all customers affected; data loss risk30 minutes4 hours
P2 โ€” HighMajor feature degraded; significant subset of customers affected2 hours8 hours
P3 โ€” MediumNon-critical feature impaired; workaround available8 business hours3 business days
P4 โ€” LowMinor issue, cosmetic, or feature request2 business daysBest effort

Response time = time from incident report to acknowledgment with assigned owner. Resolution target = time from acknowledgment to service restoration or workaround deployment. Root cause analysis for P1/P2 incidents delivered within 5 business days.

3.3 Escalation Path

Escalation LevelTimeframeContact
Level 1 โ€” Support EngineerImmediateSupport channel
Level 2 โ€” Engineering LeadAfter 2 hours (P1) / 4 hours (P2)Internal escalation
Level 3 โ€” CTO / ManagementAfter 4 hours (P1) / 8 hours (P2)Direct communication

4. Data Security and Privacy

4.1 Encryption

LayerStandard
Data in transitEncrypted on every connection, with current TLS versions only
Data at restEncrypted storage for databases, documents and backups
Passwords and secretsPasswords are stored as one-way hashes; API secrets are shown once at issuance and never stored in a recoverable form
Electronic invoicesSigned and transmitted as the NRS specification requires
Webhook signaturesEvery delivery is signed with a secret unique to your endpoint, so you can verify it came from Yona

4.2 Access Control

  • Sign-in requires a password and a second factor (authenticator app, passkey, or text-message code) on each new sign-in
  • API access uses credentials issued per environment; sandbox and production credentials are separate, shown once at issuance, and can be revoked at any time
  • Role-based permissions on all endpoints
  • Tenancy isolation enforced on the server for every request
  • All credential issuance, revocation and operator access written to an audit log
  • Rate limiting on all public endpoints

4.3 Environment Isolation

  • Sandbox and production are fully separate: separate credentials, separate data, separate webhook delivery
  • Sandbox data never crosses into production, and a sandbox credential cannot reach production

4.4 Data Retention and Deletion

  • Customer data retained for the duration of the service agreement plus any regulatory retention period
  • Data deletion upon written request, completed within 30 days, with confirmation
  • Audit logs retained for 12 months minimum

4.5 Compliance

StandardStatus
ISO/IEC 27001Certified
Nigeria Data Protection Act & NDPRCompliant

5. Change Management

5.1 Planned Maintenance

  • Scheduled maintenance communicated 48 hours in advance via email and status page
  • Maintenance windows: Sundays 02:00โ€“04:00 WAT (preferred)
  • Maximum scheduled downtime: 45 minutes per month

5.2 API Versioning

  • API is versioned (e.g., /v1/)
  • Breaking changes introduced only in new major versions
  • Minimum 90 days deprecation notice before retiring an API version
  • Non-breaking additions (new optional fields, new endpoints) deployed without version bump

5.3 Emergency Changes

  • Emergency patches (security vulnerabilities, critical bugs) may be deployed outside maintenance windows
  • Customers notified within 1 hour of emergency deployment
  • Post-incident report within 5 business days

6. Disaster Recovery and Business Continuity

MetricTarget
Recovery Point Objective (RPO)< 1 hour, through point-in-time database recovery
Recovery Time Objective (RTO)< 4 hours
Database backupsAutomated daily backups, retained for 30 days
InfrastructureDeployed across multiple availability zones for high availability
Message durabilityDurable queues; no event is lost on a service restart

7. Reporting

7.1 Availability Reports

  • Monthly uptime report provided to Customer upon request
  • Incident post-mortems for P1/P2 incidents delivered within 5 business days

7.2 Security Reports

  • Annual security review summary available upon request
  • Penetration testing conducted periodically; summary findings shared under NDA

8. Exclusions

This SLA does not apply to:

  • Sandbox environments โ€” provided on a best-effort basis
  • Third-party dependencies โ€” downtime or degradation of the Nigeria Revenue Service (NRS) or other external APIs
  • Force majeure โ€” natural disasters, government actions, internet backbone failures
  • Customer-caused issues โ€” misconfigured webhooks, invalid API usage, exceeded rate limits
  • Scheduled maintenance โ€” within the announced maintenance window

9. Term and Review

  • This SLA is effective for the duration of the service agreement
  • Reviewed annually or upon material changes to the service architecture
  • Amendments communicated 30 days in advance

Contact

Elyonar LTD

Support: support@elyonar.ng

Website: useyona.com