Regulatory

Service Level Agreement & Compliance

Last updated: 3 August 2026

This page summarises the standard Service Level Agreement (SLA) and compliance posture for Softsasi ERP. Definitive obligations are set out in the executed SLA annexed to the Master Services Agreement; this summary is provided for catalogue transparency.

1. Uptime commitments

For Softsasi-managed deployments and the API platform, monthly uptime is targeted as follows: Sandbox/Developer — best effort; Startup tier — 99.5%; Growth tier — 99.7%; Scale & Enterprise tiers — 99.9%. Uptime is measured at the application gateway, excluding scheduled maintenance windows notified at least 72 hours in advance and force majeure events.

2. Incident severity & response times

Severity 1 (production down) — initial response within 1 business hour, continuous engagement until resolution. Severity 2 (major function impaired) — response within 4 business hours, target resolution within 1 business day. Severity 3 (minor issue / workaround available) — response within 1 business day, scheduled in the next maintenance cycle. Severity 4 (cosmetic / request) — response within 3 business days.

3. Service credits

Where Softsasi fails to meet the contracted monthly uptime, service credits accrue on the affected month's fees: 5% credit for uptime below the target but ≥99.0%, 10% credit for ≥97.0%, and 25% credit below 97.0%. Credits are applied to the next invoice and are the Licensee's exclusive remedy for downtime.

4. Backups & disaster recovery

Managed environments are backed up daily with 30-day retention; weekly snapshots are retained for 90 days. Recovery Point Objective (RPO) is 24 hours and Recovery Time Objective (RTO) is 8 hours for Standard environments, with reduced RPO/RTO available under Enterprise plans. For self-hosted (on-premise) deployments, backup operations are the Licensee's responsibility; Softsasi provides reference architectures and tooling.

5. Security & data protection

Softsasi follows an ISO/IEC 27001-aligned Information Security Management System. Controls include role-based access, encryption in transit (TLS 1.2+) and at rest (AES-256), centralised audit logging, least-privilege administration, vulnerability scanning and annual penetration testing. Personal data is handled in line with applicable Bangladesh data-protection requirements and contractual confidentiality obligations.

6. Regulatory & tax compliance

The platform supports NBR-compliant invoicing (Mushak 6.3), VAT and AIT computation, statutory reporting templates, and regulator-prescribed audit trails. Compliance updates required by changes in Bangladeshi law are delivered through the AMC at no additional cost.

7. Data residency & sub-processors

Customers may select Bangladesh-based hosting for managed deployments. A current list of sub-processors and hosting locations is available on written request. Any change of material sub-processor is notified at least 30 days in advance.

8. Reporting & reviews

Enterprise customers receive a monthly service review pack covering uptime, incident summary, change management, capacity and security posture. Quarterly business reviews are conducted jointly with the customer's IT and compliance teams.

For SLA, security or compliance queries, contact support@softsasi.com.