Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours
Availability
Status
Stated plainly
- No live monitoring feed is integrated into this page. No component lights, no rolling 90-day chart, no incident history, because there is nothing yet to put in them, and a fabricated one would be the first thing on this site that was not true.
- No third party verifies Pensieve’s availability figures. When figures exist, they will be produced from Pensieve’s own monitoring, and that fact will be printed next to them.
- Monitoring measures what it is pointed at. A failure mode nobody thought to probe would not appear in these figures until a hospital reported it. This is true of every status page ever published and most do not say so.
The commitment
Availability target, by deployment model
| Service level tier | DM-1 | DM-2 | DM-3 | DM-4 | Implied maximum downtime |
|---|---|---|---|---|---|
| Standard (the default) | 99.5% | 99.5% | 99.5%, limited | No commitment | 216 minutes per 30-day service month |
| Critical (only where the Order Form records it) | 99.9% | Not offered | 99.9%, limited | No commitment | 43 minutes per 30-day service month |
Pensieve does not offer a target above 99.9% per service month. The platform runs on managed cloud services whose own published service levels are of the order of 99.95% per region per month, and a supplier cannot responsibly commit above the level of the infrastructure beneath it once its own release, configuration and dependency risk is added. A vendor offering 99.99% on a single-region deployment is either not measuring it or not honouring it. The measurement method, the twelve excluded events and the service-credit ladder are in SLA-GL-001 clause 4 and clause 8.
The boundary
DM-3 and DM-4 uptime is not Pensieve's to measure
DM-3
Customer Cloud
Infrastructure owner: Hospital.
Availability of the Pensieve-operated components is committed and measured. Unavailability caused by the hospital's own cloud project (suspension, quota exhaustion, a budget cap, an organisation policy) is excluded, and the exclusion is shown rather than silently applied.
DM-4
On-Premise
Infrastructure owner: Hospital.
Pensieve publishes no availability figure for hardware it does not own, in a room it has never entered, on a network it cannot see. The DM-4 commitment in SLA-GL-001 is limited to Pensieve's own response times. A vendor quoting the same uptime number for on-premise hardware as for its own cloud is either not thinking or not telling the truth.
This is not a caveat added to reduce liability. It is the same boundary that makes DM-3 and DM-4 worth choosing: the hospital that owns the infrastructure owns its availability, and a supplier that pretends otherwise is selling a number it cannot honour. Where a hospital wants Pensieve to carry the availability commitment, the answer is DM-1: the four models compared.
Incidents
What Pensieve commits to do, and by when
| Commitment | Clock | Basis |
|---|---|---|
| Pensieve notifies the affected hospital of a personal data breach or reportable security incident | Within 4 hours of Pensieve becoming aware | DPA-GL-001, contractual |
| A status post is opened for a confirmed Severity 1 | Within 15 minutes of confirmation | STM-GL-026 Section 1 |
| Status updates while a Severity 1 remains open | At least every 60 minutes | STM-GL-026 Section 1, POL-GL-056 |
| Post-incident review published | Within 10 business days of every Severity 1 | STM-GL-026 Section 2.6 |
| Scheduled maintenance notified in advance | Per the notice periods in SLA-GL-001 clause 10 | NTC-GL-005 |
| Pensieve reports an incident affecting its own systems to CERT-In | Within 6 hours of noticing it | CERT-In Directions of 28 April 2022, Direction (ii) |
In all four deployment models the hospital is the Data Fiduciary and holds the regulatory reporting obligation: 6 hours to CERT-In, 72 hours to the Data Protection Board. Pensieve is the processor: it supplies the content, the technical analysis and the evidence inside four hours so that the hospital can meet its own clock, and it does not represent that it reports on the hospital’s behalf. A status-page post is never a substitute for a breach notification; the two run in parallel and neither waits for the other.
Notice instruments
The notices that get sent, published in advance
Each of these is a template a hospital can read now, before it ever receives one. A notice whose wording is invented on the day of an incident is a notice written under pressure by someone with an interest in the outcome.
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours
Not yet
What appears on this page when the live feed is published
- Component status
- Application, database, integrations, authentication, background processing, reporting (each separately)
- Current incidents
- Opened within 15 minutes of confirmation, stating what is affected and what is not
- Incident updates
- At least hourly while a Severity 1 is open
- Scheduled maintenance
- Posted in advance, inside the agreed window
- Historical uptime
- A rolling 90-day view plus the permanent monthly archive
- Subscription
- Open to anyone, customer or not, without an account
It will not be gated. A prospective customer, a journalist and a competitor will see the same page a customer does: a status page visible only to customers is a marketing page. And a component is marked degraded when it is degraded, on the duty engineer’s technical signal, with no commercial approval required or sought.
Archive rules
Five rules that stop the record being improved later
- R1A published incident record is never deleted and its timeline is never altered. A correction is published as a correction, dated, with the original retained.
- R2An incident's severity is never lowered after the fact to improve a figure.
- R3A month below target is published with the same prominence as a month above it.
- R4Where an excluded window has removed time from the calculation, both the raw figure and the post-exclusion figure are shown, with the exclusion category.
- R5The archive is permanent, and it travels with the exit pack under WPR-GL-400.
These rules are published before there is a record to protect, which is the only time they can be published without looking like a response to something. They are testable, and the tests are listed in STM-GL-026 Section 6.
Sources
The documents this page renders
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: target 4 business hours