Skip to main content
This page commits one measurable SLO per customer-facing launch scenario (S1–S10) and publishes the explicit list of promises that are intentionally deferred beyond launch. Every committed number is anchored to an SLI that already exists — in scale/slos.md (SLI-1..9) or the component-level catalog at trust.mnemom.ai/slos. Unmeasured promises are flagged, not invented.
This page defines per-scenario SLOs only. Tier-based contractual uptime targets (SLA), RTO, and RPO are on SLA & Incident Response. The error-budget deploy-gating policy is tracked separately at MNE-376 and is on the deferral list below.

Per-scenario SLOs

Sign-off pending (@wassimwehbi-mnemom): all committed numbers — especially S1 (99.9% / p99 < 100 ms), S9 (≤ 30 min comms target reuse), S10 (5 min erasure p99 reuse), and S2 publish-as-target vs hold. Numbers below reflect the draft; merge is gated on sign-off.

The honest deferral list — explicitly out of launch scope

The following are not committed at launch. Each entry names the supported surface and the condition for re-evaluation.
  1. AEGIS cross-tenant adaptive layer (Managed-Rule recipe tier). The gateway runs RECIPE_MODE=shadow; cross-tenant recipes observe, never block. The seven AEGIS SLOs on trust.mnemom.ai/slos open their measurement window at GA. Per-agent protection cards are the supported launch enforcement surface.
  2. On-chain anchoring (Base L2 reputation registry + Merkle anchor). No SLO. The pipeline is fail-open with no alerting, runbook, reorg handling, or wallet monitoring. The off-chain Trust Rating is the supported launch surface; on-chain reads are best-effort verification, not a commitment. See On-chain verification for current capability scope.
  3. Managed EU data residency. The managed cloud is single-region US (Supabase). An EU data boundary requires self-host (Enterprise). A named managed EU region is deferred with no committed date.
  4. Live blocking on production traffic (the S3 enforce flip). Until MNE-231 lands, protection on production traffic is screening + verdict headers + AIP detection evidence — not synchronous blocking. No 1-10-60 detect/contain numbers are published for the blocking path.
  5. Self-serve checkout end-to-end. Trials are comped; the checkout→webhook→entitlement path carries no E2E SLO. The webhook-delivery SLO in S8 is the committed slice.
  6. /.well-known agent discovery. agents.txt is served at the web root only; /.well-known endpoints are deferred.
  7. Localized (EFIGS) documentation. The marketing site ships EFIGS; docs are English-only at launch.
  8. Per-scenario cost/COGS SLOs. Objective O9 is deferred to T1.
  9. Risk-engine SLO calibration. Risk traffic has been dry since 2026-03-09; risk-proof SLIs inherit verdict-path targets as a placeholder (scale/slos.md OQ4).
  10. Error-budget deploy-gating policy. Burn-rate alerts exist; the deploy-freeze policy is tracked at MNE-376 and is not yet in effect.

See also