managed infrastructure schedule
hosting, cloud, network, storage, backup and managed infrastructure services.
amber.systems managed infrastructure and hosting schedule
Version 2026-08-18 - last updated 18 August 2026
1. When this schedule applies
1.1 This Managed Infrastructure and Hosting Schedule applies where an Order Form incorporates it for hosting, virtual machines, containers, dedicated or accelerated compute, storage, backup, networking, DNS, content delivery, managed operating systems, managed applications, monitoring, administration or related infrastructure services (Infrastructure Services).
1.2 This schedule forms part of the Contract together with the General Terms of Business, Acceptable Use Policy, and any incorporated Service Level and Support Schedule.
1.3 Hosted applications or APIs supplied as a product may also be governed by the SaaS and API Services Schedule. Professional implementation and ongoing support apply only where expressly included.
2. Service description
2.1 The Order Form should identify, as relevant:
- allocated compute, memory, storage, network or other resources;
- service region, provider and deployment model;
- operating system, platform or application management boundary;
- included monitoring, backup, support and security functions;
- bandwidth, transfer, request or usage allowances;
- availability or recovery objectives;
- IP addresses, domains, certificates and licences;
- minimum term and committed third-party resources; and
- Customer Dependencies and excluded responsibilities.
2.2 A resource or function is not included merely because the underlying provider makes it technically available.
2.3 We may use shared, virtualised, multi-tenant or third-party infrastructure unless the Order Form expressly requires dedicated resources.
3. Shared responsibility
3.1 Responsibility depends on the management boundary in the Order Form.
3.2 Unless expressly included, the Customer is responsible for:
- application code, application configuration and data;
- users, permissions, credentials and identity-provider configuration;
- licences for Customer-selected software;
- secure use of root, administrator or control-plane access;
- patching and maintenance above the agreed management boundary;
- application-level monitoring, testing and incident response;
- the lawfulness, integrity and suitability of Customer Content; and
- independent business-continuity and recovery arrangements.
3.3 We are responsible for the infrastructure, platform or managed components expressly assigned to us, including reasonable security and maintenance within that boundary.
3.4 Shared-responsibility diagrams, runbooks and architecture records agreed by the parties form part of the service description where identified in the Order Form.
4. Provisioning and changes
4.1 We will provision Infrastructure Services using the configuration and region stated in the Order Form, subject to provider availability and Customer Dependencies.
4.2 Resource changes, migrations, region changes, operating-system upgrades and material architecture changes may affect availability, addressing, performance, Fees and data location. They require change control unless offered as an ordinary self-service function.
4.3 We may make operational changes that do not materially reduce the Service, including replacing failed hardware, changing internal routing, applying patches, moving workloads within an agreed region, or replacing a Third-Party Service with a reasonably equivalent alternative.
4.4 The Customer must not assume an IP address, hostname, hardware identifier or physical host will remain unchanged unless the Order Form expressly reserves it.
5. Access and administration
5.1 Administrative access is provided only where stated in the Order Form. The Customer is responsible for actions taken using Customer-controlled administrative credentials.
5.2 Where we hold privileged access, we will limit it to authorised personnel and use it only to provide, secure, troubleshoot and administer the Service, comply with lawful instructions, or respond to an incident.
5.3 We may require multi-factor authentication, source restrictions, key-based access, named administrators or another reasonable control for privileged access.
5.4 The Customer must not disable a security or monitoring control that forms part of the agreed managed service without our written approval.
6. Resource use, measurement and overages
6.1 The Customer must use resources within the limits, quotas and technical constraints stated in the Order Form, documentation or provider platform.
6.2 Metering generated by the relevant infrastructure or provider is authoritative unless there is a demonstrated material error.
6.3 We may apply a reasonable technical limit to protect the Service or prevent unexpected cost. Where practicable, we will provide warnings or allow the Customer to configure budgets and alerts.
6.4 Usage above an included allowance is chargeable at the rate in the Order Form or the applicable rate notified before the usage is incurred, where technically possible.
6.5 The Customer is responsible for charges caused by compromised credentials, misconfiguration or Authorised User activity, except to the extent caused by our breach. We will use reasonable efforts to limit further loss after receiving notice.
7. Network, addressing and traffic
7.1 Network performance depends on route, destination, congestion, provider peering and the public internet. Unless expressly stated, latency and throughput figures are estimates rather than guarantees.
7.2 IP addresses may be reassigned when a Service ends, changes region or is re-provisioned. The Customer must not continue announcing, routing to or representing control of an address after its allocation ends.
7.3 Reverse DNS, BGP announcements, tunnelling, anycast, bring-your-own-IP and similar functions apply only where expressly agreed and may require evidence of authority and compliance with registry or provider rules.
7.4 We may filter, rate-limit, blackhole or reroute traffic where reasonably necessary to respond to an attack, abuse report, provider instruction or material operational risk. We will limit the action to what is reasonably necessary where practicable.
8. Domains, DNS and certificates
8.1 Where we administer a domain, DNS zone or certificate for the Customer, the Customer retains responsibility for ownership, renewal funding, registrant information and lawful use unless the Order Form says otherwise.
8.2 We may use automated certificate issuance and renewal. The Customer must maintain correct DNS and validation access where those are Customer-controlled.
8.3 Domain registration, registry, certificate-authority and DNS-provider services are Third-Party Services and may be subject to their own rules and suspension processes.
8.4 We are not responsible for loss of a domain or certificate caused by inaccurate registrant information, a Customer-controlled registrar account, a registry dispute, non-payment by the Customer, or a third-party legal process outside our control.
9. Maintenance and updates
9.1 We may perform scheduled and emergency maintenance. The SLA governs any notice, measurement and availability consequence where incorporated.
9.2 For managed components, we may apply security updates, patches and configuration changes reasonably necessary to maintain security, supportability and compatibility.
9.3 Where an update creates a material compatibility risk, we will consult the Customer where reasonably possible. Urgent remediation may be applied first where delay would create a greater security or availability risk.
9.4 The Customer must keep Customer-managed components within supported versions. We may decline support, charge additional Fees or require a migration for unsupported software.
10. Monitoring, logs and security
10.1 We may collect operational, security, authentication, network, performance and usage logs needed to provide, secure and administer the Service.
10.2 Monitoring does not guarantee detection of every incident, fault or misuse. The Customer must operate any application, business and compliance monitoring not expressly included.
10.3 We may investigate an alert or suspected compromise and take proportionate protective action, including isolating a workload, revoking a credential or capturing volatile evidence.
10.4 We will notify the Customer of a confirmed material incident affecting the Customer in accordance with the Contract and DPA.
10.5 The Customer must promptly apply remediation or cooperate with containment where a Customer-managed component creates a material risk to the Service or others.
11. Backups and recovery
11.1 Backup is included only where expressly stated in the Order Form. A snapshot, replica, versioning function or provider durability claim is not a backup commitment unless described as one.
11.2 The Order Form should identify any included backup scope, frequency, retention, encryption, region, restore process, recovery-point objective (RPO) and recovery-time objective (RTO).
11.3 Unless expressly guaranteed:
- backups are a risk-reduction measure, not an archive or guarantee against data loss;
- RPO and RTO values are targets;
- restore requests may be chargeable; and
- the Customer must maintain an independent copy of data whose loss would have a material impact.
11.4 We may exclude transient, cached, derived or reproducible data from backup where documented.
11.5 The Customer should test application-level recoverability. We will test the backup process to the extent stated in the Order Form, but a successful infrastructure restore does not guarantee application consistency.
11.6 Backup copies expire through ordinary retention cycles after deletion or termination and may not be immediately purged from immutable or offline media. They remain protected and are not restored except for continuity, security or legal reasons.
12. Data location and transfers
12.1 The primary service region is stated in the Order Form or service configuration. Support, security, telemetry, replication and provider administration may involve other locations as described in the DPA and subprocessor list.
12.2 We will not materially change a committed primary data region without notice, except where necessary to protect availability, comply with law or address an urgent provider event.
12.3 The Customer is responsible for determining whether the selected region and transfer arrangements meet its legal and regulatory requirements.
13. Third-Party Services
13.1 Infrastructure Services may use providers listed in the Order Form or subprocessor list. Provider limits, maintenance, capacity and acceptable-use requirements may affect the Service.
13.2 A provider may withdraw a product, region, IP allocation or feature. We will use reasonable efforts to offer an alternative or migration path, but the Customer is responsible for unavoidable pass-through charges and application changes unless the event resulted from our breach.
13.3 Provider credits are not automatically passed through unless the Order Form says so. Where our SLA applies, the Customer’s remedy is determined by that SLA.
14. Customer Content and abuse
14.1 The Customer controls Customer Content and is responsible for its lawfulness and for responding to end-user or third-party complaints relating to it.
14.2 The AUP applies. Legitimate security research, privacy tools, encrypted communications, reverse engineering, malware analysis and other dual-use activity are not prohibited merely because of their technical nature. The authorisation and harm boundaries in the AUP still apply.
14.3 Abuse and urgent operational reports may be sent to abuse@amber.systems.
15. Availability and support
15.1 No availability percentage, response time, RPO, RTO or service credit applies unless expressly stated in the Order Form or incorporated SLA.
15.2 Planned and emergency maintenance, excluded downtime and service credits are measured under the SLA where incorporated.
15.3 Support covers the management boundary and support entitlement stated in the Order Form. Work on Customer-managed applications or unrelated systems is chargeable unless included.
16. Suspension
16.1 In addition to the General Terms, we may suspend or isolate an affected resource where reasonably necessary to:
- contain a compromise or attack;
- prevent imminent data loss or material cost;
- comply with a provider or registry instruction;
- stop activity materially affecting other customers or networks; or
- protect a resource pending clarification of authority or ownership.
16.2 Where reasonably possible, we will notify the Customer and preserve access to unaffected resources.
17. Exit, export and deletion
17.1 During the Term, the Customer may export Customer Content using available tools. A custom export, migration or conversion is chargeable unless included.
17.2 Unless the Order Form states another period, the Customer may request a standard export within 30 days after termination. We may require payment of undisputed Fees and reasonable export costs before performing additional work, but will not withhold an ordinary self-service export solely because of a disputed amount.
17.3 The Customer is responsible for validating an export and completing migration before the deletion date.
17.4 After the export period, we may delete active Customer Content and release allocated resources, addresses, domains or licences. Backup copies expire through ordinary cycles as described in section 11.
17.5 Migration assistance, data transformation, prolonged retention, media shipment, provider egress and early release from committed resources are chargeable unless included.
17.6 We do not guarantee that a Third-Party Service will support a desired export format or that a workload can be migrated without application changes.
18. Contact
- Infrastructure and service enquiries: hello@amber.systems
- Abuse and urgent operational reports: abuse@amber.systems
- Security reports concerning amber.systems: security@amber.systems