Operational metrics
Pilot-stage figures, updated by hand. We would rather say "Not measured" than publish a fabricated 100%. When automated probes land, this page will switch to live numbers and we will say so.
- Service uptime (rolling 90 days)
- Not measured
- Customer-visible incidents (rolling 90 days)
- 0
- Mean time to recover (MTTR)
- Not applicable
- Last independent penetration test
- Not yet performed
- Dependency vulnerability scan
- Every build
- Audit-trail chain breaks
- 0
Automated uptime probes deferred until first paid pilot is live. Until then, no synthetic monitoring runs and we will not report a fabricated 100%.
No customer-visible outage or data-integrity incident has been recorded in the pilot to date. Incidents (if any) are published at /status.
No qualifying incidents yet. MTTR will start being reported after the first incident.
RFP drafted at docs/canonical/19_Pen_Test_RFP.md; engagement scheduled post first paying pilot. Continuous dependency scanning (Aikido) runs on every build.
Aikido + Lovable dependency scanner run on every push. High-severity findings are remediated within the TVM-03 schedule (see /trust/caiq#tvm-03).
The audit-trail SHA-256 hash chain has never been broken in the pilot. Verifiable end-to-end at /verify with no account.
For independent verification of any pack, see /verify. For the full controls posture, see the CSA CAIQ v4 self-assessment.