Standard Service Level Agreement (SLA) for Certain QMS
Valid from September 2026
1. Purpose and scope
1.1 Purpose
This Service Level Agreement (SLA) governs Netpower Business Solutions AS’ delivery of Certain QMS (formerly Netpower Kvalitet) as a service. The agreement is intended to ensure high quality, stable operations, effective support, robust information security and predictability for the customer. The SLA sets out both Netpower’s obligations and the customer’s responsibilities, and is part of our ISO 27001-certified information security management system (ISMS).
1.2 Scope
The agreement covers:
- Operation of the application in Netpower’s data centre, including monitoring and maintenance of the infrastructure.
- Maintenance, management and further development of the application itself, including source code, bug fixes, security patching, updates and the release of new versions.
- User support, troubleshooting and error correction according to defined severity levels.
- Uptime guarantee and compensation arrangements.
- The process for handling support cases from registration to closure.
- An option for an extended on-call phone service with round-the-clock cover.
- Specific provisions for custom functionality and for operation on the customer’s infrastructure.
2. Definitions
- Uptime: The time the service is available from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in section 9 are not included.
- Response time: The time from a case is registered in Zendesk until troubleshooting has started. The SLA guarantees the start of troubleshooting, not the resolution time.
- Severity levels: P1 (critical), P2 (high), P3 (medium), P4 (low), see section 6.
- ISMS: Netpower’s information security management system, certified to ISO 27001.
- Custom functionality: Functions or views developed specifically for one customer, which are not part of the standard version.
- Customer-operated infrastructure: Cases where the application runs in the customer’s own environment or data centre instead of Netpower’s data centre.
3. Operating environment and security
Netpower operates the service from its own primary data centre in Stavanger, with backups stored off-site at a separate location, and with a high level of physical and logical protection.
3.1 Physical and logical security
- Access control (personal card and code), security guard patrols, video and motion surveillance.
- Redundant power supply (UPS and diesel generator with automatic start).
- Redundant cooling and continuous climate control.
- Fire and humidity detectors and an Inergen fire suppression system.
3.2 Infrastructure and redundancy
- High Availability (HA) available, with load balancing and failover configuration.
- Redundant network with at least two independent internet connections.
- Infrastructure designed for high availability and fast recovery from failures.
3.3 Server operation and patching
- All servers are operated with established routines for operating system and security patching.
- Critical updates and zero-day vulnerabilities are handled with expedited patching outside the regular service window when the risk calls for it.
- IDS/IPS rules, antivirus and anti-malware are updated continuously.
- Firewalls are configured according to the principle of least privilege and are continuously updated with new signatures.
3.4 Monitoring and incident management
- Servers, networks and services are monitored continuously, with automatic alerts for downtime, performance and security events.
- Incidents are handled according to established procedures in Netpower’s ISMS, including logging, analysis and escalation when needed.
- Critical incidents are reported immediately and handled in accordance with the SLA.
All of these measures are part of Netpower’s ISO 27001-certified ISMS. The operating environment and security routines are reviewed annually and updated continuously to meet new threats, vulnerabilities and regulatory requirements.
4. Support model, opening hours and channels
4.1 Support levels
- 1st line service desk: Receives requests, triage, user support and simple error correction.
- 2nd line: Application specialists and system engineers with expertise in the operating environment and the application.
- 3rd line: Developers and architects with in-depth knowledge of the application architecture and code.
In addition to the regular support model, customers have access to extensive self-service resources:
- Help pages at help.certainqms.com, with up-to-date documentation and user guides.
- Training videos available from the help pages and often built directly into the customer’s own application.
- Contextual help in the application: From each module, users can click the help icon (?) and go straight to the relevant documentation for that functionality.
During implementation and the project phase, the customer has direct access to the project team, including consultants and developers, and should not use the service desk for project-related questions during this period.
4.2 Opening hours and channels
The service desk is staffed on weekdays 08:00–16:00. During these hours the support centre can be reached by phone on +47 51 95 80 00, by email at support@certainqms.com or support@netpower.no, and through our online support system, either by creating a case or by live chat.
- The primary channel is Zendesk (online support system).
- Email and phone can be used, but incoming and outgoing requests are always logged in Zendesk.
- At peak times, the phone queue is routed to additional staff to reduce waiting time.
5. Support case process
All support cases are handled according to an established process in Netpower’s service desk. The process ensures that cases are assessed, prioritised and followed up in a predictable way, and that the customer is always kept informed.
- The customer registers a case in Zendesk (primary channel). Alternatively by email or phone, which is always logged in Zendesk.
- A ticket ID is created and the customer automatically receives a receipt with the time and reference.
- All cases are monitored continuously by service desk staff throughout the day. Severity (P1–P4) is assessed as soon as the case is registered.
- Troubleshooting is started by the 1st line. If the error cannot be resolved there, the case is escalated to the 2nd or 3rd line, with the work done so far documented.
- P1 cases are escalated immediately and given the highest priority. Netpower assigns the best-suited resources at once, including product owners and system architects, so that the combined expertise is mobilised quickly. Other tasks are put aside until the case is under control.
- Communication: All communication about a support case takes place in Netpower’s support system (Zendesk). This gives full overview, history and traceability for both the customer and Netpower. For P1 cases, phone may also be used for quick clarification, but all updates and decisions are always logged in Zendesk.
- For larger customers, Netpower can give the customer’s system owner access to see and follow all cases registered from the organisation. This gives an overview of status and progress, and helps ensure that costs never come as a surprise.
- When the case is resolved, closure is confirmed with the customer. Documentation and a description of the solution are provided when required or requested.
Security-related P1 incidents are also handled as information security incidents in line with the ISMS incident management procedure, including notification, root cause analysis and corrective actions.
6. Severity and response time (start of troubleshooting)
Response time is the time from a case is registered in Zendesk until troubleshooting has started. The SLA guarantees the start of troubleshooting, not the resolution time.
| Severity | Standard SLA (08–16) | Extended SLA (on-call phone option) | Description and typical cases |
|---|---|---|---|
| P1 Critical | 1 hour | 30 min (24/7) | Total downtime or unavailability of the application. No users can log in or carry out critical processes. Critical security incidents that threaten the confidentiality, integrity or availability of data. Example: the whole system is down, the database is unavailable, a serious data breach. |
| P2 High | 2 hours | 1 hour (24/7) | Significant functionality out of service for many users, but not total downtime. Workarounds exist, but business-critical processes are affected. Example: registering nonconformities does not work, major performance problems that prevent work, an integration with a critical third party fails. |
| P3 Medium | 4 hours | 4 hours (08–22, incl. weekends) | Functionality is reduced or affects some users, but core processes still work. Not business-critical. Example: an error in the report function, limited performance problems, errors in single modules that have a workaround. |
| P4 Low | 1 day | N/A | Cosmetic errors, user questions, minor errors or improvement requests that do not affect operations. Example: an error in screen text, setting up a new user, a requested configuration adjustment. |
Errors related to user synchronisation and access management
Certain QMS can be integrated with the customer’s identity environment (for example Azure AD or other AD solutions) using standards such as SCIM. In such cases, access problems may be caused by factors outside the application itself, for example changes in the customer’s identity directory, synchronisation routines or configuration.
- Errors that can be traced to the customer’s identity environment are not considered application errors under this SLA.
- Response time and severity for such cases are assessed in dialogue between Netpower and the customer, and classified according to the actual cause and consequence.
- Netpower assists with troubleshooting and guidance to identify the cause, but operational responsibility for running and configuring the identity environment lies with the customer.
7. Uptime guarantee
Netpower guarantees 99.8% uptime per calendar month. Uptime is measured from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in section 9 are not included. Uptime measurement and deviation reporting are part of the ISMS and can be made available for audit.
8. Service window
Primarily Wednesday 23:59 – Thursday 05:59. Downtime does not occur automatically in this window; Netpower plans work to cause as little disruption as possible.
9. Exceptions from uptime measurement
The following are not considered a breach of the uptime guarantee:
- Downtime caused by the customer or by faults in the customer’s equipment.
- Downtime at the customer’s request.
- Force majeure / natural disasters.
- Restarts, security updates and maintenance.
10. Compensation for SLA breaches
Netpower is committed to delivering the services in line with this SLA, and we take responsibility if the delivery does not meet the defined targets. To give the customer predictability and confidence, the following compensation scheme applies:
- If the 99.8% uptime guarantee is not met in a calendar month, or
- If less than 90% of cases in the month are handled within the agreed response times,
… the customer will receive automatic compensation in the form of a credit on the monthly fee.
Compensation level:
- 5% reduction of the monthly fee per breach.
- Total compensation per month is capped at 15% of the monthly fee.
Principles:
- The compensation is intended to reflect reduced service quality and to give the customer financial balance when targets are missed.
- The credit is applied on the following invoice, clearly shown as a separate line.
- The compensation is standardised and automatic, so the customer does not need to make a separate claim.
- This scheme is a minimum safeguard for the customer and comes in addition to the customer’s rights under the main agreement.
11. Backup and disaster recovery
- Netpower takes daily backups of production data. Standard hosting includes 7 days of retention before overwriting. The customer can order extended retention of up to 21 days for an additional fee.
- Restore tests are carried out periodically and according to established routines in our ISO 27001-certified ISMS. Results are documented and reviewed as part of the annual audit.
- Disaster recovery plans are established, documented and part of the ISMS. The plans are reviewed annually, and testing is carried out according to risk assessment and customer needs.
12. Change management and new versions
- Change requests are registered and estimated on an ongoing basis in dialogue with the customer.
- New versions and updates are made available to all licence customers.
- Upgrades are normally carried out in the agreed service window, taking care to preserve customer adaptations.
- The customer may choose to stay on the current version for a limited period, but Netpower reserves the right to require an upgrade when this is necessary for reasons of security, stability, maintainability or regulatory requirements.
- Critical security updates and bug fixes are always distributed, and may be installed outside the service window when needed.
- Versions older than a defined life cycle (typically 12–18 months) are no longer supported, and the customer must upgrade to a newer version. Netpower always gives notice of life cycles and support periods in good time.
- Netpower ensures that customer adaptations are taken care of during upgrades, and helps the customer with any clarifications needed in advance.
- If critical vulnerabilities or security improvements are identified, Netpower reserves the right to upgrade or patch the application outside the service window. This is done to protect information security and reduce the risk of service interruption or data loss. The customer is informed as soon as possible before, during and after such an upgrade.
13. Custom functionality
For some customers, Certain QMS is delivered with custom functionality or tailored views developed specifically for the customer’s needs. Such deliveries offer great flexibility, but also involve particular conditions:
- Troubleshooting and error correction: Custom solutions may take longer to analyse and fix than standard functionality, as it may be necessary to involve developers who know the specific adaptation.
- Upgrades: The risk that custom functionality is affected by upgrades is higher than for the standard version. Netpower will do its best to preserve the adaptations, but cannot guarantee full compatibility with every new version. Any necessary adjustments are agreed with the customer.
- Response time: Cases registered on custom functionality are handled according to the SLA response times, but resolution time may vary more than for standard functionality. The customer is always kept informed of progress and expected time to resolution.
- Maintenance: Netpower recommends that custom solutions are reviewed regularly with the customer to ensure compatibility with new functionality and security updates.
Custom work gives customers added value, but may mean that support, upgrades and error correction require more time and coordination than for the standard solution.
14. Security, risk assessments and audits
- Netpower is ISO 27001-certified and has established an ISMS.
- Annual risk assessments are carried out for the application and the operating environment.
- The application is risk-assessed at every major release.
- Annual penetration testing of Certain QMS is carried out.
- Customers can receive a copy of penetration test and risk assessment reports on request.
- External security audits are carried out regularly.
- Netpower assists customers with penetration and vulnerability tests and audits.
15. Customer responsibilities and participation
The customer shall:
- Provide the access and information Netpower needs to deliver the service in accordance with the agreement.
- Ensure the quality of the data in its own records.
- Give feedback without undue delay.
- Use the application for the purpose it was developed for, and in line with applicable laws, regulations and internal routines.
- Ensure that access control and user administration follow the need-to-know principle, and that unauthorised or unintended use of the system does not take place.
- Not use the application for purposes other than those agreed, or store information that is clearly unsuitable for the system (for example sensitive personal data, unless agreed in writing).
Netpower is responsible for delivering a secure and stable solution in accordance with this SLA and the main agreement. The customer is responsible for how the solution is used internally, and for any consequences of incorrect use, inadequate access control or storing information beyond what the system is intended for.
16. Limitation of liability
Limitation of liability is governed by the main agreement between Netpower and the customer.
For clarity, Netpower cannot be held liable for errors caused by the customer’s own data, the customer’s systems or third-party deliveries.
17. Option: On-call phone / extended SLA
For an additional fee, the customer can order an on-call phone service.
- Purpose: The on-call phone exists to ensure that the application is available and that the operating services in Netpower’s data centre are working. The service only covers incidents where the application or the server environment is unavailable (P1).
- Not covered: The on-call phone does not cover user support or correction of functional errors that can be handled within regular opening hours. Such cases must be registered in Zendesk and are handled according to this SLA.
- Availability: Weekdays 16:00–22:00, weekends and public holidays 09:00–22:00.
- 24/7 option: For P1 incidents (system completely unavailable), a separate 24/7 agreement can be made.
- Registration: Zendesk is always available 24/7/365 for registering cases.
18. Information security and ISO 27001
- All services covered by this SLA are delivered within Netpower’s information security management system (ISMS), which is certified to ISO/IEC 27001.
- The ISMS ensures a systematic approach to information security, including risk management, security controls, ongoing monitoring and continual improvement.
- Netpower carries out annual risk assessments of the application, the operating environment and related processes. In addition, the application is risk-assessed at every major release to ensure that new versions do not introduce unacceptable risk.
- Annual penetration testing of Certain QMS is carried out by external security partners. Results are assessed and followed up in line with the ISMS.
- Customers can receive a copy of the certificate, as well as reports from completed risk assessments and penetration tests, on request and with due regard for confidentiality.
- Security incidents are handled according to a defined process for information security incidents, including escalation, notification, root cause analysis and documented corrective actions.
- Netpower sets corresponding requirements for subcontractors, and supply chain security is followed up in accordance with ISO 27001 Annex A 5.19.
- Disaster recovery plans and contingency routines are established and reviewed annually.
- Continual improvement of information security is part of the ISMS, and Netpower is committed to following up new threats, vulnerabilities and regulatory requirements.
19. Other provisions
Subcontractors, force majeure and dispute resolution follow the provisions of the main agreement.
20. Customer-operated infrastructure
For some customers, Certain QMS runs on the customer’s own infrastructure or in the customer’s internal data centre. In such cases, the following specific provisions apply:
- Netpower is not responsible for physical security, redundancy, power supply, cooling, monitoring or backup of the customer’s operating environment. These are the customer’s responsibility.
- Netpower depends on the customer providing the access needed to carry out updates, troubleshooting or other work. Response times in this SLA are counted from the time such access is given.
- Netpower cannot guarantee the same uptime or readiness as in Netpower’s own data centre, as this depends on the customer’s infrastructure and routines.
- The customer must ensure that the operating environment meets minimum requirements for security and performance, and that Netpower receives sufficient notice and access when needed.
This section applies only to customers where the application runs on the customer’s own infrastructure or data centre.
