Enterprise terms of service
These terms apply to enterprise licences issued through the Ittisal licence server. They set out the service commitment, the isolation guarantees and the obligations on both sides.
Availability and response commitments
| Commitment | Target | Remedy or note |
|---|---|---|
| Monthly platform availability | 99.99% | Service credits against the monthly licence fee, scaled by shortfall |
| Severity 1 acknowledgement | 15 minutes, 24/7 | Queue down, no inbound audio, or total API failure |
| Severity 2 acknowledgement | 2 working hours | Degraded channel or a failing flow on live traffic |
| Standard ticket first response | 4 working hours | Sunday to Thursday, 09:00–18:00 GST |
| Post-incident report | 5 working days | Written cause, timeline and corrective actions for severity 1 |
| Announced maintenance | 72 hours notice | Friday 01:00–03:00 GST, excluded from availability calculation |
Availability is measured per hosting region from synthetic probes at one-minute resolution. Service credits are the exclusive remedy for availability shortfalls.
Tenant isolation policy
Every request resolves its tenant once, at the edge of the request lifecycle, and then executes under that resolved context. A tenant hint that disagrees with the authenticated session is refused and logged as a security event rather than corrected silently.
Only platform system roles may cross a tenant boundary, the target tenant is verified before the request proceeds, and each crossing is written to an audit trail available to both tenants. Credentials, channel tokens and encryption keys are held per tenant and are not readable across boundaries even when the same connector class is in use.
- Tenant resolved server-side; never taken from a client payload
- Disagreeing tenant hints refused and logged
- Cross-tenant access limited to verified platform system roles
- Per-tenant credential encryption with rotation outside the image
Use, term and termination
The licence is granted for the deployment, channel mix and seat count stated in the order, and is enforced through the licence server. Entitlements are visible to your administrators, and exceeding them raises a notice rather than interrupting live traffic.
Term is annual unless stated otherwise, renewing by agreement. On termination, tenant data is exported in machine-readable form on request and then deleted from managed infrastructure within 30 days; self-hosted deployments retain their own data by definition.
- Licence scoped to deployment, channels and seats stated in the order
- Overage raises a notice; live traffic is not interrupted
- Export on request, then deletion within 30 days of termination
- Flow documents and configuration are exportable at any time
What each side is responsible for
Ittisal is responsible for the platform, its availability, the security measures described in the privacy policy, and second-line support on flows we built.
The tenant is responsible for the lawfulness of the conversations it automates, consent and recording notices where required, the accuracy of data written into its own systems, and administration of its users and API keys. These terms were last updated in September 2026; material changes are notified 30 days ahead.