← Governance framework
Platform Operations

Change Management and SLA Policy

How changes to the platform are proposed, reviewed, deployed and communicated, and the service levels users can expect.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
CTO
Approver
Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
338c3d3f64ccb22ab815873841f542ef98131f4016f3bf7af4152583f23683ab
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:338c3d3f64ccb22a

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All production changes

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Peer-reviewed migrations for every schema change
  • GRANT + RLS + policy required for every new public table
  • Feature flags for staged rollout

1. Change Types

  • Standard - pre-approved, low risk, deployable on demand.
  • Normal - reviewed by CAB equivalent (Executive + Trust Committee where relevant).
  • Emergency - expedited path with post-hoc review.

2. Service Levels

  • Target uptime: 99.9% monthly for public verification endpoints.
  • Support acknowledgement: 1 business day.
  • Privacy request completion: within statutory deadlines.
Questions or concerns about this policy? Contact the DPO.

Related policies