Firms run live mediations on DétenteIQ, so availability and a quick, competent response when something needs attention are not extras — they are the product. This is how the service is kept running, watched, backed up, and supported.
Application errors are captured and surfaced as they happen, with the context needed to fix them, and availability is measured independently rather than on our own say-so.
A backup that has never been restored is treated as unproven, which is why we test it rather than assume it. Recovery runs from documented procedure, not from one person's memory.
Issues are reported through the in-application Support tool, by email, or by phone for urgent matters, and every issue is assigned a severity with a committed time to engage. The response target is a commitment to acknowledge, confirm severity, and own the issue; for a critical issue, work continues until service is restored.
| Severity | Response target |
| Critical — service unavailable, a live mediation blocked, or a data-integrity or security concern | 2 hours, incl. after-hours |
| High — a major function impaired with no workaround | Same business day |
| Normal — a function degraded, workaround available | 2 business days |
| Low — a question, cosmetic issue, or request | 5 business days |
Continuity is deliberately built so that operating and recovering the service is a matter of following documented procedure rather than reconstructing knowledge that lives in one person's head. The system is documented end to end in a written operations runbook covering deployment, backup and restore, rollback, and incident response.
Your data is yours. It is exportable in a standard, usable format at any time on request, so a firm can leave with its own records at any point, independent of the company's status. Reasonable transition assistance is available under the agreement.
A firm's IT, risk, or procurement team can evaluate DétenteIQ on paper before a single call. Three are available to download now; the Data Processing Addendum and full security questionnaire we share on request, under NDA where appropriate.
Availability target, severity levels, and response commitments.
↓ PDFRecovery objectives, tested backups, and continuity of operations.
↓ PDFHow the service is built, encrypted, and isolated — standard and zero-knowledge.
Pre-answered across the domains a SIG Lite or CAIQ covers.
Processor terms, technical measures, and the subprocessor list.
The full detail is on our Security page →
Independent uptime monitoring · error and disk alerting · nightly encrypted off-instance backups · quarterly restore tests · minute-scale rollback · documented runbooks · a defined support SLA.
A third-party penetration test and a SOC 2 examination, and additional infrastructure redundancy as the client base grows. We'll state each here, with the date, as it is completed.
We'll share the SLA, the business-continuity summary, the security questionnaire, and the DPA, sign the NDA, and walk your IT and risk teams through any of it directly.