Status · probed every 5 minutes

Operational now. October is below its 99.5% commitment.

Operational. The last probe found every endpoint up, inside its latency budget, and returning the pinned answer. Each probe asks the production data API fixed questions about a synthetic family, over the public internet like any client, and compares every answer’s hash with the one pinned for the engine in service. A wrong number counts as an incident, the same as an outage. Last probe: 2026-10-02 06:05 UTC.

Availability

How often has every check passed?

WindowProbes passedProbesAvailability
Last 24 hours27528895.486%
Last 7 days1,7661,77999.269%
Last 30 days (10.4 days measured)2,9262,97898.253%
Last 90 days (10.4 days measured)2,9262,97898.253%
Calendar monthProbesFailedAvailabilityFailures the commitment allowsBudget leftCredit the terms owe
2026-10 (in progress)3621396.408%10not yet: the month is open
2026-092,6163998.509%13025% of that month's fee

Committed to clients: 99.5% a calendar month, with credits below it. The credit column is computed from this record by the schedule in the order form, not negotiated afterwards: below 99.5% it is 10% of that month’s fee, below 99.0% it is 25%. The error budget is the number of probes a month may still fail before the committed figure is breached. Target: 99.9%. The committed figure sits below the target on purpose until this record is ninety days long. A window with no probes shows a dash, not a hundred. Figures are floored, never rounded up. The record began 2026-09-21 20:05 UTC; the first month counts from then. Every failure in it stays, and each incident’s cause is reviewed below.

Latency · last 24 hours · measured from outside

How long does each answer take?

EndpointMedian95th percentileBudget
Book as known83 ms121 ms2,500 ms
Concentration across entities404 ms579 ms4,000 ms
Exposures384 ms552 ms2,500 ms
Health149 ms336 ms2,000 ms
Capital-call simulation (2,000 paths)543 ms777 ms6,000 ms
Rebalancing endpoint stays off71 ms121 ms2,500 ms
Lot sequence337 ms758 ms4,000 ms
Incidents · last 48 hours in detail

What went wrong, and for how long?

StartedEndedAboutChecks that failed
2026-10-02 04:50 UTC2026-10-02 05:55 UTC65 minBook as known: up; Concentration across entities: up; Exposures: up; Health: engine named; Health: isolation; Health: up; Capital-call simulation (2,000 paths): up; Rebalancing endpoint stays off: says why; Rebalancing endpoint stays off: up; Lot sequence: up

The checks: up (the expected status), fast (inside the budget above), the same twice (asked again, the same hash), right (the hash pinned for this engine), honest (the answer still says it executes nothing), shut (401 without a token). Engine in service: e67542034c7ae8dc…. The same record as JSON, for your own monitor: /api/status. Try the questions yourself on the developers page; the controls behind the platform are on Trust.

Incident reviews · since the record began

Why each one happened, and what stops it now.

2026-09-23 22:20 UTC → 2026-09-24 01:05 UTC · 33 failed probes

Cause. A new engine (12fea765…) went live before its pinned answers did, so every answer failed the check against the pin until the pin was deployed.

What changed. Both ways production is deployed, CI and the release script, now refuse an engine whose answers are not pinned.

2026-09-22 00:50 UTC → 2026-09-22 01:20 UTC · 6 failed probes

Cause. A route change added a field to the lot-sequence answer on an unchanged engine, so its bytes no longer matched the pinned hash.

What changed. The answer's bytes were restored within the hour, and every change is now compared with the pinned answers before it is pushed.

A review explains a failure; it does not remove one. Every failed probe above still counts in its month’s figure.