• Platform
    • Platform overview
    • How it works
    • Cloud Controller
    • Secure NAT gateway
    • GWLB inspection
    • Compliance
  • Landing zones
    • All landing zones
    • AWS landing zones
    • Azure landing zones
    • AWS Marketplace
    • Azure Marketplace
  • Compare
    • All comparisons
    • Versus Azure Firewall
    • Versus AWS Network Firewall
    • NAT gateway alternative
    • Azure Firewall cost
    • AWS NAT Gateway cost
    • Savings calculator
  • Pricing
  • Partners
    • Partner programme
    • MSSP and MSP
    • Resellers
    • White-label firewall
Book a demo Start free
  • Platform

    • Platform overview
    • How it works
    • Cloud Controller
    • Secure NAT gateway
    • GWLB inspection
    • Compliance
    • PCI DSS firewall
    • SOC 2 firewall
    • Firewall audit
    • Articles
  • Landing zones

    • All landing zones
    • AWS landing zones
    • Azure landing zones
    • AWS Marketplace
    • Azure Marketplace
  • Compare

    • All comparisons
    • Versus Azure Firewall
    • Versus AWS Network Firewall
    • NAT gateway alternative
    • Azure Firewall cost
    • AWS NAT Gateway cost
    • Savings calculator
    • Versus alterNAT
    • AWS Network Firewall cost
    • Azure NAT Gateway cost
    • Azure Firewall cost example
    • Google Cloud NGFW cost
  • Pricing
  • Partners

    • Partner programme
    • MSSP and MSP
    • Resellers
    • White-label firewall
Start free Book a demo

Legal · Service Level Agreement

Service Level Agreement

Version 2.0 (draft) · Synvu Limited, trading as Enforza

DRAFT — for review only, not in force. Prepared for solicitor review. Not published; does not replace the SLA currently in force. It will not go live until (1) a solicitor has reviewed it and (2) the Licence redline repointing the SLA definition at this URL ships. (The uptime-monitoring service, decision 1.8, is now confirmed: an Enforza-operated monitor in a separate cloud region with a public status page at status.enforza.io/status/enforza.)

1. About this agreement

1.1 This Service Level Agreement (SLA) is the "Service Level Agreement" referred to in the Enforza Software Licence Agreement published at https://enforza.io/terms-of-service/ (the Licence). It forms part of the Licence and is to be read with it.

1.2 Words and expressions defined in the Licence have the same meaning in this SLA unless this SLA says otherwise.

1.3 If this SLA conflicts with the Licence, the Licence prevails, except where this SLA expressly states that it varies a specified clause of the Licence.

The SLA presently in force says the opposite. Its clause 1.1 provides that "the terms and conditions of this SLA shall prevail" over the Licence. That inverts the normal hierarchy and puts a two-page subordinate document above the main contract. Note S11 sets out why reversing it is the right answer and what is lost by doing so.

1.4 If this SLA conflicts with an Order countersigned by Enforza and the Licensee, that Order prevails to the extent of the conflict.

1.5 Version. This SLA is version v2.0 (draft), effective 2026-08-23. Enforza will publish a version identifier and effective date on every published revision of this SLA, and will retain superseded versions at stable URLs.


2. Additional definitions

The following definitions apply in this SLA in addition to those in the Licence:

Business Hours means 09:00 to 18:00 UK local time (GMT or BST as applicable), Monday to Friday, excluding days that are bank holidays in England and Wales.

Business Day means a day on which there are Business Hours.

Control Plane means the Enforza-operated services that the Enforza Agent connects to, including the Console at console.enforza.io, the GitOps interface at gpi.enforza.io, and the APIs and messaging services supporting them.

Customer Environment means the Devices, the operating systems, virtual machines, networks, cloud accounts and Platform Dependencies on or through which the Enforza Agent runs, all of which are the Licensee's responsibility under clause 6.1 of the Licence.

Support Request means a request for Support Services submitted in accordance with section 6.2.

Severity means the severity level assigned to a Support Request under section 6.4.


3. Scope — what Enforza operates and what the Licensee operates

3.1 This section defines the boundary of every commitment in this SLA. It is not background.

3.2 The Enforza Platform is deployed in two parts:

PartOperated byPaid for by
The Enforza Agent, running on a Device inside the Customer Environment — the component that actually inspects and forwards trafficThe LicenseeThe Licensee, directly to its own cloud provider or hosting provider
The Control Plane — where policy is authored, validated, distributed and observedEnforzaIncluded in the Subscription Fee

3.3 The Enforza Agent holds a single outbound connection to the Control Plane. It accepts no inbound management connections.

3.4 Consequence, which the Licensee should understand before relying on this SLA: if the Control Plane becomes unavailable, a Device that is already running

continues to enforce the policy last applied to it, and continues to pass traffic. What the Licensee loses is the ability to author, apply, validate or observe policy until the Control Plane is restored. Traffic enforcement is not interrupted by a Control Plane outage.

3.5 Accordingly, every availability commitment in this SLA is a commitment about the availability of the Control Plane. Enforza makes no availability commitment in respect of:

  • 3.5.1 any Device, or the throughput, latency, capacity or uptime of any Device

(clause 6.1 of the Licence places the underlying infrastructure, its sizing and its patching on the Licensee);

  • 3.5.2 the Customer Environment, including any cloud provider, hypervisor,

network or Platform Dependency;

  • 3.5.3 the correctness or effect of any policy or firewall rule authored by the

Licensee (clause 6.1 of the Licence places configuration on the Licensee); or

  • 3.5.4 any third-party service to which the Licensee directs logs or telemetry,

including the Licensee's own SIEM.

3.6 This section states expressly what the SLA presently in force leaves implied. That document applies its availability commitment to "the Enforza Platform" without qualification — a term the Licence defines as "the firewall management platform (including Enforza Agent)", so on its face the commitment extends to software running on the Licensee's own infrastructure. Its own clause 8 then excludes "any periods where your firewall or gateway is offline", and its clause 9.2 records that "the firewalls and gateways will continue to operate on the last successfully deployed policy". Both carve-outs only make sense on the boundary set out in this section 3. Section 3 states the boundary rather than leaving it to be inferred from two exclusions. See note S12.


4. Availability of the Control Plane

The 99.8% figure below is the figure presently in force. It is carried across from the SLA in force unchanged — see the SLA currently in force, clause 2.1. It is not a new commitment and not a drafting proposal. What has changed is what it applies to, marked at 4.1 and explained at note S12.

4.1 Availability Service Level. Enforza shall use commercially reasonable efforts to make the Control Plane available with a monthly uptime percentage of at least 99.8% (the Availability Service Level).

4.2 Measurement. Availability is measured as a percentage of each calendar month in which the Control Plane is Available, calculated as:

Availability % = ((Total Minutes in Month − Unavailable Minutes) ÷ Total Minutes in Month) × 100

4.3 Available means the Control Plane accepts and responds to requests such that an Authorised User can author and apply policy and an Enforza Agent can establish and maintain its outbound connection.

4.4 Measurement method. Availability is determined by reference to Enforza's uptime monitoring service, which runs on infrastructure independent of, and in a different cloud region to, the Control Plane, measured over each monthly calendar period. The monitoring results are published continuously at Enforza's status page: status.enforza.io/status/enforza.

4.5 Unavailable Minutes exclude any period of unavailability caused by or attributable to:

  • 4.5.1 planned maintenance notified in accordance with section 4.6;
  • 4.5.2 emergency changes made in accordance with section 4.7;
  • 4.5.3 an Event Outside Our Control within the meaning of clause 13.2 of the

Licence;

  • 4.5.4 anything within section 3.5 — including the Customer Environment, any

Device, the Licensee's equipment, software or technology, any third-party equipment, software or technology, and any period during which the Licensee's firewall or gateway is offline or otherwise compromised;

  • 4.5.5 the Licensee's failure to comply with or implement Enforza's instructions

regarding use of the Enforza Platform or the Licensee's operating systems and networks;

  • 4.5.6 any third-party service provider, including any internet service

provider, and any failure or degradation of a public cloud provider, network or telecommunications service used by Enforza, to the extent Enforza could not reasonably have avoided its effect ;

  • 4.5.7 the Licensee's breach of the Licence, or suspension of the Licensee's

access under clause 3.3, clause 4.3 or clause 11 of the Licence ; and

  • 4.5.8 use of the Enforza Platform other than in accordance with the Licence,

the Documents or the Specification .

4.6 Planned maintenance. Enforza may carry out planned maintenance on not less than 48 hours' notice to the Licensee. Enforza will use reasonable endeavours to schedule planned maintenance outside Business Hours. Unavailability during planned maintenance does not count toward the Availability Service Level.

4.7 Emergency changes. Where there is an actual or potential security threat, or any issue affecting the availability of the Enforza Platform, Enforza may perform emergency changes at any time without prior notice. Unavailability resulting from an emergency change does not count toward the Availability Service Level.

4.8 Relationship to clause 10.4 of the Licence. Clause 10.4 of the Licence states that Enforza does not warrant that use of the Services will be uninterrupted or error free. The commitment in section 4.1 is an exception to clause 10.4 to the extent expressly stated in this section 4, and only in respect of the Control Plane.


5. Service credits

The ladder below is the ladder presently in force, carried across unchanged from the SLA currently in force, clauses 6 and 7. The only changes are the two boundary corrections at note S15, which repair defects in the existing table rather than alter the commercial position.

5.1 Where the Availability Service Level is not met in a monthly calendar period, the Licensee is entitled to a service credit calculated as a percentage of the Subscription Fee for that month:

Monthly uptime achievedService Credit
Below 99.8% but not below 99.0%5% of the monthly Subscription Fee
Below 99.0% but not below 98.0%10% of the monthly Subscription Fee
Below 98.0% but not below 96.0%15% of the monthly Subscription Fee
Below 96.0%20% of the monthly Subscription Fee

5.2 Claiming. The Licensee must request a service credit within 30 days of the end of the monthly calendar period in which the triggering event occurred. A credit not requested within that period is not payable.

5.3 Cap. Service credits will not exceed 20% of the monthly Subscription Fee in any month, regardless of the total downtime in that month.

5.4 Form of credit. Service credits are applied against future Subscription Fees only. No refund or cash compensation will be issued.

5.5 Sole and exclusive remedy. Service credits as described in this SLA are the Licensee's sole and exclusive remedy, and Enforza's entire liability, for any failure by Enforza to meet the Availability Service Level.

5.6 Section 5.5 does not apply to the response and update targets in section 6, which carry no service credit or other financial remedy at all — see section 7.


6. Support Services

This section is the "Support Services" described in the definition of Support Services in clause 1.1 of the Licence, and provided under clause 2.10 of the Licence with reasonable skill and care.

6.1 Support hours

6.1.1 Support is provided during Business Hours — 09:00 to 18:00 UK local time, Monday to Friday, excluding bank holidays in England and Wales.

6.1.2 Severity 1 Support Requests are handled on a best-efforts basis 24 hours a day, 7 days a week, including outside Business Hours. This is a best-efforts arrangement, not a staffed rota, and section 7 applies to it.

6.2 How to raise a Support Request

6.2.1 Support Requests are raised by email to support@enforza.io. This is the only supported channel. Requests raised by any other route — including direct messages to individuals, social media, or comments in a shared repository — are not Support Requests and no response time applies to them.

6.2.2 A Support Request should state: the affected organisation and Device or Devices, what was observed and when, what was expected, whether production traffic is affected, whether a workaround is in place, the proposed Severity, and a contact for the response.

6.2.3 Enforza may ask for further information reasonably required to diagnose the issue, including logs and configuration. Where Enforza has asked for information and is waiting for it, the update obligations in section 6.5 are suspended until it is provided.

6.3 Severity definitions

Severity is determined by observed effect, not by the Licensee's commercial urgency and not by which component is at fault.

SeverityApplies where
S1 — CriticalAny of: (a) an Enforza Agent on a production Device has stopped passing traffic, or is passing or blocking traffic materially contrary to the policy applied to it, and no workaround is available; (b) the Control Plane is unavailable to the Licensee and the Licensee needs to apply or change policy in order to respond to a live security incident or an imminent production outage; or (c) a defect in the Enforza Platform is actively exposing the Licensee's traffic or Licensee Data, or is actively permitting traffic that the applied policy prohibits.
S2 — MajorAny of: (a) production traffic is materially affected but a workaround is available and in place; (b) the Control Plane, Console or GitOps interface is unavailable or so degraded that policy cannot be authored, applied or validated, while deployed Devices continue to enforce the policy last applied to them; (c) a material Feature is unavailable or significantly degraded; or (d) delivery of logs or telemetry from the Enforza Platform to the Licensee's chosen destination has stopped.
S3 — MinorAny of: (a) limited loss of function with no material effect on production traffic; (b) a fault affecting a non-production environment only; (c) a defect in reporting, display or documentation; or (d) a question about observed behaviour of the Enforza Platform.
S4 — RequestNo fault is reported. Requests for information, configuration guidance, documentation, a change to a Subscription or account, or a feature request.

Applying the table:

  • 6.3.1 A Control Plane outage on its own is S2, not S1. Devices continue to

enforce the policy last applied to them and continue to pass traffic (section 3.4). It becomes S1 only under limb (b) of S1 — where the Licensee needs to change policy to deal with something live and cannot.

  • 6.3.2 S1 requires production impact. A Support Request affecting only a

non-production, test, staging or evaluation environment is S3 by default, whatever its effect in that environment, unless Enforza agrees otherwise in writing.

  • 6.3.3 A cause within section 3.5 does not by itself reduce Severity. Where

production traffic is affected, the Support Request is graded on that effect even if the cause turns out to be the Customer Environment. Section 6.7 governs what happens once the cause is established.

6.4 Assigning and re-grading Severity

6.4.1 The Licensee proposes a Severity when raising the Support Request.

6.4.2 Enforza confirms or re-grades the Severity in its first response, applying section 6.3, and states its reason for any re-grade.

6.4.3 Where the Licensee and Enforza disagree on Severity, the higher of the two proposed Severities applies until the disagreement is resolved. This prevents the response clock being lost to an argument about grading.

6.4.4 A Support Request may be re-graded downwards once a workaround is in place and operating, or once the effect that justified the original grade has ceased. Enforza will tell the Licensee when it does so and why.

6.5 Target response and update times

SeverityTarget first responseTarget update frequencyClock
S1 — Critical4 hoursevery 4 hours while the Support Request remains open at S1Best efforts, 24/7
S2 — Major1 Business Daydaily, each Business Day, while open at S2Business Hours
S3 — Minor2 Business Daysevery 2 Business Days while open at S3Business Hours
S4 — Request5 Business DaysnoneBusiness Hours

How the clocks run:

  • 6.5.1 The clock starts when the Support Request is **received at

support@enforza.io**.

  • 6.5.2 For S1, the clock runs continuously, including outside Business

Hours, on the best-efforts basis in section 6.1.2 and section 7.

  • 6.5.3 For S2, S3 and S4, the clock runs only during Business Hours. A

Support Request received outside Business Hours is treated as received at the start of the next Business Hour.

  • 6.5.4 If a Support Request is re-graded under section 6.4, the response and

update targets for the new Severity apply from the time of the re-grade. A first response already given is not given again.

  • 6.5.5 Clocks are suspended while Enforza is waiting on information it has

reasonably requested from the Licensee under section 6.2.3.

6.6 Response only — no resolution or workaround commitment

6.6.1 The times in section 6.5 are response and update times. They are not resolution times. Enforza does not commit, at any Severity, to resolve a Support Request, to provide a workaround, or to do either within any period.

6.6.2 Enforza will use reasonable endeavours to resolve Support Requests, in Severity order, consistent with clause 2.10 of the Licence.

6.7 What is outside the Support Services

Enforza is not obliged to provide Support Services in respect of anything for which the Licensee is responsible under clause 6.1 of the Licence, including the Customer Environment, the sizing, patching and availability of Devices, the Licensee's own firewall rules and policies, backups of firewall configuration, and Platform Dependencies. Enforza may assist with such matters at its discretion; doing so does not create an obligation to do so again.

Enforza is also not obliged to provide Support Services in respect of: use of the Enforza Platform other than in accordance with the Licence, the Documents or the Specification; any version of the Enforza Agent that Enforza has notified as no longer supported; or any modification to the Enforza Agent not made or approved by Enforza.

6.8 Escalation

6.8.1 Where two consecutive updates due under section 6.5 have been missed on an open S1 or S2 Support Request, the Licensee may escalate directly to:

Neil Briscoe, Chief Technology Officer, Synvu Limited t/a Enforza escalations@enforza.io

6.8.2 Escalation is a route to a named person. It does not change the Severity, the targets in section 6.5, or the status of those targets under section 7.


7. Status of the commitments in this SLA

7.1 The response and update times in section 6.5 are targets. They are given on a best-efforts basis. They are not warranties, conditions or guaranteed service levels.

7.2 There is no service credit, refund, price reduction or other financial remedy for a failure to meet a target in section 6.5. Section 5 deals with service credits, and section 5 is concerned with availability under section 4 only.

7.3 Failure to meet a target in section 6.5 is not of itself a breach of the Licence. Enforza's obligation in respect of Support Services is the obligation in clause 2.10 of the Licence — to provide them with reasonable skill and care.

7.4 Clause 10 of the Licence (Limitation of Liability) applies to this SLA in full.

7.5 Nothing in this section 7 limits or excludes any liability that cannot be limited or excluded by law, and clause 10.7 of the Licence applies.


8. Changes to this SLA

8.1 Enforza may update this SLA from time to time on not less than 14 days' notice (the Change Notice Period). This SLA forms part of the Licence, so a change to it is a change to the terms of the Licence and clause 12.1 of the Licence applies: if the Licensee does not wish to accept the change, it must notify Enforza at contact@enforza.io within the Change Notice Period, whereupon the Licence terminates. Continued use after deemed service of notice under clause 12.3 of the Licence constitutes acceptance.

The document in force says that on non-acceptance "the SLA shall immediately terminate", not the Licence. That leaves the Licensee on a Licence whose definitions of Service Level Agreement, Support Services and Service Credits all point at a document that has terminated — still paying, with no support terms and no availability commitment. Note S16 explains why aligning to clause 12.1 is the fix.

8.2 Enforza will publish a version identifier and effective date with each revision, and retain superseded versions at stable URLs, so that a Licensee can establish what was in force on a given date.

8.3 Where a countersigned Order states an agreed period during which a term of this SLA will not be varied to the Licensee's detriment, that Order prevails.


9. Contact

Supportsupport@enforza.io
Escalationescalations@enforza.io (Neil Briscoe, CTO)
Contractual noticescontact@enforza.io

Enforza is a product and trading name of Synvu Limited, a company registered in England and Wales (Company No. 15761962), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.


← Back to enforza.io

The built-for-cloud firewall — same capability as the cloud-native one, at 60–80% less. Flat, per firewall, no per-GB data-processing tax.

Runs on any cloud.

Product

  • Platform
  • Cloud Controller
  • How it works
  • Landing zones
  • AWS landing zones
  • Azure landing zones
  • Secure NAT gateway
  • NAT gateway alternative
  • AWS GWLB Inspection
  • DigitalOcean egress filtering
  • Hetzner Cloud egress firewall
  • AWS Marketplace
  • Azure Marketplace

Compliance

  • Compliance hub
  • PCI DSS firewall
  • SOC 2 firewall
  • HIPAA firewall
  • ISO 27001 firewall
  • NIST firewall rules
  • Firewall audit

Compare

  • All comparisons
  • vs AWS Network Firewall
  • vs Azure Firewall
  • vs Google Cloud NGFW
  • vs OCI Network Firewall
  • vs pfSense
  • vs OPNsense
  • vs fck-nat
  • vs alterNAT
  • vs Aviatrix
  • vs Cisco Multicloud Defense

Pricing

  • Pricing
  • Savings calculator
  • AWS Network Firewall cost
  • Azure Firewall cost
  • Azure Firewall cost example
  • AWS NAT Gateway cost
  • Azure NAT Gateway cost
  • Google Cloud NAT cost
  • Google Cloud NGFW cost

Partners

  • Partner program
  • Reseller program
  • MSSP / MSP platform
  • White-label firewall
  • Multi-tenant firewall

Company

  • About
  • Contact
  • Articles

© 2026 Synvu Limited. All rights reserved.

  • Terms of Service
  • Privacy Policy
  • DPA
  • Sub-processors

Enforza is a trading name of Synvu Limited, a company registered (15761962) in the United Kingdom. Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

AWS and the “Powered by AWS” / AWS Marketplace logos are trademarks of Amazon.com, Inc. or its affiliates. Microsoft, Azure and the Azure logo are trademarks of the Microsoft group of companies. Google Cloud and all other product and company names, logos and trademarks referenced on this site are the property of their respective owners. Enforza is an independent product and is not affiliated with, endorsed by, sponsored by, or otherwise associated with Amazon Web Services, Microsoft, Google, or any other company mentioned here. All third-party names and marks are used solely for identification and comparison purposes.

We use cookies to measure traffic and, with your consent, support advertising — both stay off until you allow them. See our Privacy & Cookie Policy.