← Governance framework
Platform Operations
Change Management and SLA Policy
How changes to the platform are proposed, reviewed, deployed and communicated, and the service levels users can expect.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- CTO
- Approver
- Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
338c3d3f64ccb22ab815873841f542ef98131f4016f3bf7af4152583f23683abSHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:338c3d3f64ccb22aThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All production changes
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Peer-reviewed migrations for every schema change
- GRANT + RLS + policy required for every new public table
- Feature flags for staged rollout
1. Change Types
- Standard - pre-approved, low risk, deployable on demand.
- Normal - reviewed by CAB equivalent (Executive + Trust Committee where relevant).
- Emergency - expedited path with post-hoc review.
2. Service Levels
- Target uptime: 99.9% monthly for public verification endpoints.
- Support acknowledgement: 1 business day.
- Privacy request completion: within statutory deadlines.
Questions or concerns about this policy? Contact the DPO.