Status
What Sonar depends on, and what you will hear when one of them breaks.
This page is the honest version of a status page for a product that has not launched. It tells you what a workspace depends on, what you would actually see when one of those parts is degraded, and what we commit to telling you. It does not tell you whether anything is up right now, because nothing is watching yet and a green dot that meant nobody is looking would be the worst thing on this site.
Nothing outside Sonar is watching Sonar
An external monitor at status.sonar.pritect.ai, hosted away from the infrastructure it reports on, is the next step and it has not been taken. Until it has, the table below says what each part does for you and who would notice first if it stopped, which is what we can say truthfully today.
| Component | Where | What you see when it stops | Watched |
|---|---|---|---|
| The application | EU, Frankfurt | Nobody can sign in or read an inventory. Scans that are already running carry on, because the worker does not go through the application, and a finding written while you were locked out is there when you get back.No external monitor is provisioned yet. The status host named below is the owner's next step, and until it exists the honest answer to whether the application is up is that you would find out by opening it. | Not yet |
| The scanning worker | EU, Frankfurt | No new findings. A scan stops where it is and resumes from its checkpoints when the worker returns, so an interrupted scan costs time rather than coverage, and nothing is read twice.The worker answers a health check on its own machine and nothing outside it asks yet. A scan stuck with no queued job is noticed in the database rather than by a monitor, every minute, which is a different guarantee and a narrower one. | Not yet |
| The database | EU, Frankfurt | Everything stops at once: the application, the worker and the read API all read from it. Nothing is lost, because a job that cannot write does not complete and is redelivered.The managed provider watches its own availability. Nothing of ours watches it from outside, so a partial failure would show as slowness rather than as an incident. | Not yet |
| Contextual classification | EU endpoint | Scans continue and the deterministic layer keeps working. Items that needed the second pass end as needs review rather than as clean, which is slower to act on and is the only safe way round: there is no path from unknown to clean without a rescan.An item that ended as needs review is listed as needs review in your inventory, so the effect of an outage is visible where you work rather than only on a status page. A rescan is how it gets its second pass once the model is answering again. | Not yet |
| Your Microsoft 365 tenant | Yours, wherever Microsoft holds it | Enumeration and reads slow down or stop. Microsoft throttling is normal and handled: the connection backs off, says so on its health panel, and resumes. A revoked consent is different and the connection says that too.Connection health is checked on a schedule and shown on the connection page. Microsoft's own service health is published by Microsoft and is not mirrored here. | Not yet |
| The Pritect platform feed | EU, Ireland | Only if you have linked the two products. Findings keep being written in Sonar and the feed catches up when the platform answers again, because it is a queue and not a live call.An administrator sees the undelivered count and the age of the oldest on the platform feed page in Sonar. That is the signal, and there is no alert on it yet. | Not yet |
What happens when something breaks
These four are commitments this build can keep today rather than intentions. The first is a term of the data processing agreement, and the others are properties of how the product is put together.
You hear from us, we do not wait to be asked
An incident that affects your workspace is told to the administrators of that workspace. A personal data breach is told to you within twenty four hours of us becoming aware, which is the term in the data processing agreement and not a softer promise made here.
What an incident report says
What happened, when it started and when it ended, which components were affected, what it meant for your scans and your findings, whether any personal data was involved, and what we changed so it does not happen again. Weakest part first, in the same register as the rest of this site.
What a breach of Sonar could expose
There is no document content to expose, because none is kept. What could be exposed is the inventory: where personal data lives, in what categories and quantities, the filenames and paths concerned, how they are shared, and the account that owns a container. That is a real exposure and the data processing agreement describes it in those terms rather than minimising it.
Your own record is yours, and it is separate from ours
Every change to a workspace is in its own audit log, which an administrator can read and export at any time, incident or no incident. Nothing on this page replaces it, and a status page nobody can check against their own records is a status page you have to take on faith.
What this page does not claim
- A live status host
- There is not one yet. When it exists it will live at status.sonar.pritect.ai, it will be hosted away from the infrastructure it reports on, and this page will link to it. A status page served by the thing it is reporting on tells you nothing on the day it matters.
- An uptime figure
- None is published, because nothing has been measured. A percentage here before there is a monitor behind it would be a number nobody could check, which is the same rule that keeps an accuracy figure off the limits page.
- A service level agreement
- There is no uptime commitment at this stage, and the terms of service say so rather than leaving it to be inferred. A customer who needs one asks for it in the contract.
- Historical incidents
- There are none to show. Sonar has no production customers yet, so an empty history here is the true history and not a page that has been tidied.
- Email alerts
- Sonar sends no email at all yet, for incidents or anything else. Notifications are written and readable in the product, and the notification preferences page says the same thing in the same words.