Escalation and vault release are the two things that must never quietly fail, so they are reported separately from everything else.
Accepting taps from app, watch and email.
Evaluating windows and dispatching the ladder.
Push, email, SMS and automated voice.
Sealed item storage and recipient key wrapping.
Account, roster and vault management.
Every incident that affected any part of the service in the last twelve months, including those that never reached a user.
A queue backlog at our push provider delayed first-rung reminders by up to 43 minutes. No escalation rung advanced early or late as a result — the ladder is evaluated server-side against wall-clock time, not delivery time. Backfilled and resolved.
A failed database migration put the web dashboard into read-only mode. Check-ins from the app and escalation dispatch were unaffected throughout. Rolled back and resolved.
An upstream carrier rejected messages to some UK numbers on the second escalation rung. Affected accounts fell through to the automated call rung as designed. Provider failover added afterwards.
Uptime is measured against escalation correctness, not server reachability. A window that should have advanced a rung and didn't is downtime even if every server stayed up. A dashboard outage that never touched the ladder is reported, but does not count against the figure above.