Service Level Agreement
1 Agreement Overview
This Service Level Agreement (“SLA”) defines the performance standards, availability commitments, and support obligations that Go2Solve Limited (“Provider” or “Go2Rev”) will deliver to customers (“Customer” or “Taxpayer”) using the Go2Rev Access Point Provider Platform (“Service”).
This SLA ensures timely, reliable, and secure e-invoicing services that meet regulatory standards established by the Federal Inland Revenue Service (FIRS) and the Nigeria Revenue Service (NRS).
2 Service Description
Go2Rev provides a certified Access Point Provider (APP) platform that enables Nigerian businesses to comply with FIRS e-invoicing mandates. The Service includes:
- API Gateway — RESTful API endpoints for programmatic invoice submission
- Web Portal — Browser-based interface for manual invoice creation and submission
- NRS Integration — Secure transmission channel to FIRS infrastructure
- Invoice Management — Storage, retrieval, search, and audit capabilities
- Webhook Notifications — Real-time status updates via HTTP callbacks
- Compliance Reporting — Automated monthly compliance and audit reports
- Developer Tools — API documentation, sandbox environment, SDKs
3 Service Availability
Maximum allowable downtime: 21 minutes per month. Measured in UTC at 1-minute intervals across multiple geographic locations.
3.1 Uptime Calculation
Monthly Uptime % = (Total Minutes − Downtime Minutes) ÷ Total Minutes × 100
3.2 Exclusions from Downtime
The following are excluded from downtime calculations:
- Scheduled Maintenance — Announced ≥7 days in advance; conducted 1:00 AM–4:00 AM WAT; limited to 4 hours/month
- FIRS/NRS Infrastructure Downtime — Unavailability of FIRS servers beyond Go2Rev’s control
- Customer-Side Issues — Network failures, invalid API keys, malformed requests
- Force Majeure Events — Natural disasters, war, power grid failures
- Emergency Security Patches — Critical updates required to protect Customer data
- Customer-Requested Downtime — Maintenance requested by Customer
3.3 Planned Maintenance
- Maximum twice per month, up to 2 hours per window
- 7 days advance notice via email and dashboard
- Scheduled between 1:00 AM–4:00 AM WAT on weekends
- Emergency maintenance may proceed with 24 hours’ notice for critical security issues
4 Performance Standards
4.1 API Response Times
| Metric | Standard | Measurement |
|---|---|---|
| P50 Latency | < 200ms | 50th percentile response time |
| P95 Latency | < 500ms | 95th percentile response time |
| P99 Latency | < 1,000ms | 99th percentile response time |
Measured from API Gateway receipt to response transmission. Excludes network transit time between Customer and Go2Rev servers. Applies to invoice submission, retrieval, and status check endpoints.
4.2 Invoice Processing Time
4.3 Webhook Delivery
| Metric | Standard |
|---|---|
| Initial Delivery Attempt | Within 30 seconds of event |
| Retry Attempts | 3 retries with exponential backoff (1s, 5s, 30s) |
| Success Rate | 98% delivery within 5 minutes (for reachable endpoints) |
4.4 Dashboard Load Time
- Initial Page Load: < 2 seconds (P95)
- Data Refresh: < 500ms for metric updates
5 Support Services
5.1 Support Tiers
- ChannelsEmail
- Response24 biz hours
- CoverageMon–Fri, 8am–6pm WAT
- Escalation48 hrs (critical)
- ChannelsEmail, Live Chat
- Response4 biz hours
- CoverageMon–Fri, 8am–8pm WAT
- Escalation12 hrs (critical)
- Account Mgr✓ Assigned
- ChannelsEmail, Phone, Chat, Slack
- Response1 hr (24/7 critical)
- Coverage24/7/365
- Escalation2 hrs (critical)
- Tech Acct Mgr✓ Assigned
- QBRs✓ Included
5.2 Severity Levels
| Severity | Definition | Response Time (Enterprise / Business / Startup) | Resolution Target |
|---|---|---|---|
| Critical | Complete outage; no invoices can be submitted | 1 hr / 4 hrs / 12 hrs | 4 hours |
| High | Major functionality impaired; many users affected | 4 hrs / 8 hrs / 24 hrs | 24 hours |
| Medium | Partial functionality impaired; limited user impact | 8 hrs / 24 hrs / 48 hrs | 72 hours |
| Low | Minor issue; workaround available | 24 hrs / 48 hrs / 5 biz days | Best effort |
5.3 Support Contact
- Email: support@go2rev.com
- Phone (Enterprise): 0909 139 0626
- Live Chat: Available via Go2Rev Dashboard
- Status Page: status.go2rev.com
6 Security & Compliance
6.1 Data Security
- Encryption in Transit: TLS 1.3 for all API communications
- Encryption at Rest: AES-256 encryption for all stored data
- Credential Storage: Encrypted via AWS Secrets Manager or HashiCorp Vault
- Access Controls: Role-based access control (RBAC) with MFA
- Audit Logging: Immutable audit trail for all data access and modifications
6.2 Compliance Standards
| Standard | Status / Details |
|---|---|
| FIRS APP Certification | Maintained and renewed annually |
| NDPR Compliance | Full compliance with Nigeria Data Protection Regulation |
| SOC 2 Type II | Target certification within 12 months of service launch |
| Data Residency | All production data stored in Nigeria (AWS af-south-1) |
| Data Retention | 10 years for invoice data (exceeds 7-year FIRS requirement) |
6.3 Security Incident Response
- Customer notified within 24 hours of a confirmed security incident
- Detailed post-incident report within 5 business days
- Go2Rev handles NITDA notification as required by NDPR
7 Data Backup & Disaster Recovery
7.1 Backup Policy
- Automated backups every 6 hours
- 30-day retention for incremental backups; monthly backups retained for 1 year
- Encrypted backups stored in a geographically separate region (EU)
- Backup restoration tested quarterly
7.2 Disaster Recovery
| Objective | Target | Notes |
|---|---|---|
| Recovery Point Objective (RPO) | 1 hour | Maximum data loss |
| Recovery Time Objective (RTO) | 4 hours | Maximum downtime |
| Automated Failover | Within 30 seconds | Database failover |
| Geographic Redundancy | Multi-AZ deployment | — |
8 Service Credits
8.1 Credit Schedule
| Monthly Uptime % | Credit (% of Monthly Fee) |
|---|---|
| 99.95% – 99.50% | 10% |
| 99.50% – 99.00% | 25% |
| 99.00% – 95.00% | 50% |
| < 95.00% | 100% |
8.2 Credit Request Process
- Submit request within 30 days of the calendar month in which downtime occurred
- Include: affected account details, date/time of unavailability (WAT), and supporting logs or screenshots
- Go2Rev reviews and responds within 10 business days
- Approved credits applied to the next monthly invoice
- Credits are Customer’s sole remedy for SLA breaches
8.3 Credit Limitations
- Maximum credit: 100% of monthly subscription fee
- Credits do not apply to usage-based (per-invoice) fees
- Credits are non-transferable and non-refundable as cash
- No credit for free-tier or trial accounts
9 Customer Responsibilities
To receive SLA guarantees, Customer must fulfil the following obligations:
9.1 Technical Requirements
- Maintain valid NRS credentials and update promptly when changed
- Implement proper error handling and retry logic in API integrations
- Configure webhook endpoints to accept HTTPS connections
- Monitor API rate limits and adjust usage accordingly
- Report suspected issues within 48 hours of occurrence
9.2 Security Requirements
- Safeguard API keys and never expose them in public repositories
- Enable MFA for all user accounts
- Rotate API keys every 180 days (recommended)
- Comply with FIRS e-invoicing regulations and submission timelines
9.3 Account Management
- Keep contact information current for service notifications
- Respond to Go2Rev security notifications within 24 hours
- Maintain sufficient account balance for paid tiers
- Notify Go2Rev of any suspected unauthorized access
10 Rate Limits & Fair Use
10.1 API Rate Limits
| Tier | Rate Limit | Burst Allowance |
|---|---|---|
| Startup | 100 req/min | 150 req/min |
| Business | 500 req/min | 750 req/min |
| Enterprise | 1,000 req/min | 1,500 req/min |
| Custom | Negotiated | Negotiated |
10.2 Invoice Volume Limits
| Tier | Monthly Invoice Limit |
|---|---|
| Startup | 10,000 invoices |
| Business | 100,000 invoices |
| Enterprise | Unlimited |
10.3 Fair Use Policy
Go2Rev reserves the right to throttle or suspend accounts engaged in:
- Excessive API polling (> 1 request/second for status checks)
- Automated attacks or security testing without prior authorisation
- Submission of invalid or test data to the production FIRS environment
- Reselling or unauthorised sub-licensing of the Service
11 Service Modifications
11.1 Service Updates
- Minor Updates: Deployed without notice (bug fixes, performance improvements)
- Major Updates: 30-day advance notice for breaking API changes
- Feature Additions: Generally available immediately; notifications via changelog
- API Versioning: Deprecated versions supported for minimum 12 months
11.2 SLA Modifications
- Go2Rev may modify this SLA with 60 days’ written notice
- Modifications reducing SLA commitments require Customer acceptance
- Continued use after the modification effective date constitutes acceptance
- Enterprise customers may negotiate custom SLA terms
12 Termination & Data Portability
12.1 Service Termination
- Customer-Initiated: 30 days’ written notice required
- Provider-Initiated: 90 days’ notice for non-breach termination
- For Cause: Immediate termination for material breach, non-payment, or illegal activity
12.2 Data Export
- Self-service export in CSV, Excel, JSON, PDF via dashboard (available anytime)
- Full account data export provided within 30 days of termination request
- Data retained in archived state for 90 days post-termination, then permanently deleted
- Customer remains independently responsible for 10-year FIRS retention obligation
13 Limitation of Liability
13.1 Service Credits as Sole Remedy
Service Credits outlined in Section 8 are Customer’s sole and exclusive remedy for any SLA breach or service unavailability.
13.2 Liability Cap
Go2Rev’s total liability for any claims arising from this SLA shall not exceed the total fees paid by Customer in the 12 months preceding the claim.
13.3 Exclusions
Go2Rev is not liable for:
- Loss of business, revenue, profits, or data
- Indirect, consequential, special, or punitive damages
- Issues arising from FIRS/NRS infrastructure failures
- Customer’s failure to comply with FIRS regulations
- Third-party service failures (hosting providers, telecommunications)
14 Monitoring & Reporting
14.1 Real-Time Status
- Status page updated in real-time: status.go2rev.com
- 90-day incident history publicly available
- Optional email/SMS alerts for service disruptions
14.2 Monthly Uptime Reports
- Available to Business and Enterprise tiers
- Published within 5 business days of month end
- Includes: uptime percentage, incident summary, performance metrics
14.3 Service Health Dashboard
Customers can monitor in real-time:
- API availability status
- Current response time metrics
- FIRS connectivity status
- Queue processing health
- Scheduled maintenance windows
15 Definitions
| Term | Definition |
|---|---|
| Downtime | Period when the Service is unavailable and returns HTTP 5xx errors for 3 consecutive minutes |
| Monthly Uptime % | Calculation defined in Section 3 |
| Business Hours | Monday–Friday, 8:00 AM–6:00 PM WAT, excluding Nigerian public holidays |
| Service Credit | Monetary credit applied to Customer’s account as compensation for SLA breaches |
| Critical Issue | Severity 1 incident as defined in Section 5.2 |