SLAs, limits and quotas

The reference page for procurement and architecture review: Spikefrost's uptime commitment and support response times, Cloudflare's underlying Workers SLO with its exclusions quoted in full, every platform limit, and current compliance posture.

The Spikefrost Team30 Jul 20266 min read

Everything a procurement or architecture review needs, in one place. Three sections deliberately kept separate: our commitment to you, Cloudflare's commitment to us, and the hard technical limits neither of us can change by agreement.

1. Spikefrost service level agreement

Applies to app serving — your deployed application responding to requests on its platform URL or custom domain.

Term Commitment
Monthly uptime 99.9%
Allowed downtime 43 minutes 49 seconds per month
Measurement Monthly, per app, based on failed requests attributable to the platform
Remedy Service credits, below

Service credits

Monthly uptime achieved Credit against that month's fee
99.0% – 99.9% 10%
95.0% – 99.0% 25%
Below 95.0% 50%

Support response

Severity Definition First response Coverage
Sev-1 Service unavailable 1 hour 24/7
Sev-2 Major feature degraded 4 hours Business hours
Sev-3 Question or minor issue 1 business day Business hours

What the uptime commitment excludes

Standard, and stated so there are no surprises during an incident review:

  • Faults in your application code, including returning your own 5xx responses
  • Your configuration — firewall rules, blocked paths, maintenance mode, misconfigured bindings or secrets, custom domain DNS
  • Exceeding a documented platform limit or quota
  • Suspension for non-payment, or for breach of acceptable use
  • Scheduled maintenance announced in advance
  • Force majeure, and failures in networks outside our and Cloudflare's control

Control-plane availability — deploys, the CLI, the dashboard, agent dispatch — is handled under the support severities above rather than the uptime credit, because a control-plane incident does not stop a deployed app from serving traffic. See Failure domains.

2. Cloudflare's underlying commitment

Spikefrost apps run on Cloudflare. Their commitment to us is a component of ours to you, not a substitute for it — and its scope is narrower than most people assume, so it's quoted rather than summarized.

Term Value
Workers Service Level Objective 99.99% monthly uptime
How measured Error Rate Percentage — non-custom 500, 502, 503, 504 responses from provisioned Workers, excluding throttled or rate-limited requests
Credits 99.9%–99.99% → 10% · 95%–99.9% → 25% · below 95% → 50%
Source Cloudflare Workers SLA

The exclusion that matters most

The Service Level Objective does not apply to unavailability resulting from "…incorrect configuration of bindings (e.g., KV, Durable Objects, D1, or R2, etc.), mismanaging Workers secrets, or exceeding resource limits", nor from "unavailability or performance degradation of interdependent Cloudflare services" — including the CDN, DNS, WAF, and storage bindings.

In other words: the 99.99% covers the compute path, not the storage your app depends on. This is why our own commitment sits below it, and why Failure domains treats graceful degradation as a design requirement rather than an optimization.

3. Platform limits

Current Cloudflare limits on the paid plans Spikefrost apps run on. These are technical ceilings, not contractual terms.

Compute — Workers

Limit Value
Memory per isolate 128 MB (JS heap + WebAssembly)
CPU time per request 30 s default, configurable to 5 min
Wall-clock time Unlimited while the client is connected
waitUntil after response 30 s
Cron, queue consumer, DO alarm wall time 15 min
Global-scope startup budget 1 s
Script size 10 MB gzipped (64 MB uncompressed)
Subrequests per request 10,000
Environment variables / secrets 128 per Worker, 5 KB each

Database — D1

Limit Value
Database size 10 GB
Storage per account 1 TB
Databases per account 50,000 (raisable by request)
Point-in-time recovery window 30 days
Queries per Worker invocation 1,000
Maximum query duration 30 s
Maximum row / string / BLOB size 2 MB
Columns per table 100
SQL statement length 100 KB
Rows per table Unlimited within the size cap

Coordination — Durable Objects

Limit Value
Storage per object (SQLite) 10 GB
Classes per account 500
Objects per class Unlimited
CPU per request 30 s default, to 5 min
Alarm / background wall time 15 min
WebSocket message size 32 MiB (received)
Row / string / BLOB size 2 MB

Spikefrost-level quotas

Limit Value Why
App source tree 256 MB Source only — media belongs in assets, data in the database
Analytics retention 3 months Aggregate metrics, sampled
Request-log body capture 14 days, opt-in Off by default; JSON and text only, secrets redacted
Environments per app Unlimited Created on first deploy
Queues per app 10 Plus a dead-letter queue each
Managed email senders per app 5 Transactional sending only

Note on the analytics dataset: Cloudflare samples Analytics Engine data automatically and does not guarantee retrieval of any individual record. Weight aggregates by the sampling interval. For exact events use request logs; for business outcomes use your app's own event feed in D1. See Observability and audit.

4. Compliance posture

Item Status
SOC 2 Type II Attested — report available under NDA
ISO 27001 Certified — certificate available on request
GDPR Data processing agreement available; sub-processor list on request
Data residency guarantees Not offered today. Compute runs in the Cloudflare location nearest the user
Bring-your-own Cloudflare account Not available today
HIPAA Not claimed

Where something isn't offered, it says so. If residency or dedicated tenancy is a hard requirement, raise it before you build — see Isolation and tenancy.

Recovery objectives

Summarized from Durability and recovery:

Scenario RPO RTO
Database corruption or bad write ~0 within the 30-day window Minutes
Bad deploy 0 — code is versioned ~1 minute
Accidental file deletion 0 — every version retained Seconds to minutes
Durable Object state loss Unbounded — no point-in-time recovery Unbounded unless mirrored to D1
KV value loss Unbounded Rebuild from source of truth

Verifying any of this yourself

Nothing here requires trusting the page:

sf deployments                  # deploy history and outcomes per environment
sf d1 history                   # available point-in-time bookmarks
sf logs --since 24h --errors    # what your app actually returned
sf analytics query "SELECT ..." # your own metrics
curl -sSI https://your-app.example.com/ | grep -i x-sf-   # version + cache state

Last reviewed: 30 July 2026. Cloudflare's published limits and SLA change; where this page and their documentation disagree, theirs is authoritative and we want to know so we can correct this.

Next

Frequently asked questions

What uptime does Spikefrost commit to?

99.9% monthly uptime for app serving — about 43 minutes of allowed downtime per month — with service credits of 10%, 25%, or 50% depending on the shortfall.

Why is Spikefrost's SLA lower than Cloudflare's 99.99%?

Because it covers more. Cloudflare's 99.99% applies to the Workers compute path and excludes storage bindings; our commitment covers app serving end to end, so it leaves headroom for the parts Cloudflare excludes and for our own control plane. A higher number would promise more than our upstream guarantees.

Are these limits negotiable?

The Cloudflare platform limits are mostly fixed, though some — database count, for instance — can be raised by request. Spikefrost-level quotas such as the app source budget can be discussed. Ask before you architect around a limit you find inconvenient.

Is a control-plane outage covered by the uptime SLA?

The uptime commitment covers app serving — your deployed application responding to requests. Deploys, CLI, and dashboard availability are handled as support severities rather than uptime credits, because a control-plane incident does not stop your app from serving traffic.

Which compliance certifications exist today?

SOC 2 Type II and ISO 27001, and a GDPR data processing agreement is available. Reports and certificates are shared under NDA — ask your account contact.