TopSyde
Free malware scannerGet your free site auditStart Risk-Free

Your Uptime Guarantee Allows 43 Minutes Down a Month

Most hosting uptime guarantees exclude maintenance, DDoS and customer-caused outages. Read the fine print, run the credit math, and know what to ask before you sign.

Marcus Webb

Marcus Webb

DevOps & Security Lead

··10 min read

Last updated: September 29, 2026

Magnifying glass over a hosting service level agreement document showing uptime exclusion clauses

A 99.9% uptime guarantee permits 43 minutes and 50 seconds of downtime every month without the host owing you anything. Beyond that, most contracts exclude scheduled maintenance, DDoS attacks, third-party network faults and anything labeled customer-caused, then pay the remainder in account credit you have to request in writing within 30 days.

What does a 99.9% uptime guarantee cover?

It covers the availability of the server, measured the host's way, over a calendar month, minus a list of exclusions. It does not cover your site being slow, your checkout failing, your forms silently not sending, or your admin being locked out while the homepage still returns a 200.

Here is what the percentages buy you in real minutes.

GuaranteeAllowed downtime per monthPer yearTypical marketing claim
99.0%7 hours 18 minutes3 days 15 hours"Reliable shared hosting"
99.9%43 minutes 50 seconds8 hours 45 minutes"Three nines uptime"
99.95%21 minutes 54 seconds4 hours 22 minutes"Business tier"
99.99%4 minutes 23 seconds52 minutes"Enterprise SLA"

The gap between 99.9% and 99.99% is the difference between a bad afternoon and a coffee break. Most hosts advertise the first number in 48-point type and price the second as an enterprise add-on.

Then there is the measurement question. If the host polls its own server from inside its own data center every five minutes, a four-minute outage never happened. Ask what interval they measure at and from how many external locations. Our guide to WordPress uptime monitoring tools and incident response walks through why one-minute checks from multiple regions give you numbers you can actually argue with.

What gets excluded in the fine print?

The exclusion list is where the guarantee goes to die. Every major host has one, usually in section 4 or 5 of the service agreement, and the categories repeat across the industry almost word for word.

Scheduled maintenance. Any window the host announces in advance, often with as little as 24 hours notice, does not count against uptime. Some agreements reserve a standing weekly window.

Emergency maintenance. The same exemption, minus the notice requirement. A host that patches a kernel bug at 2pm on a Tuesday has not breached anything.

DDoS and abuse events. Attack traffic against your site or a neighbor on the same infrastructure is excluded almost universally, even though absorbing that traffic is the job you thought you were paying for.

Upstream and third-party failures. DNS providers, CDN outages, transit carriers, registrar problems. If the fault is one hop outside the host's network, it is your problem. This is why checking DNS before assuming your WordPress site was hacked matters so much during an incident: the cause determines whether anyone owes you anything.

Customer-caused downtime. The broadest clause in the document. A plugin update that white-screens the site, a bad .htaccess rule, a PHP version bump, exceeding a resource limit you were never told about. All customer-caused.

Suspensions. Downtime during a billing or terms-of-service suspension is excluded, which is a problem when the suspension itself was premature. We covered a case where an account was suspended two weeks before the invoice was even due, and the SLA offered exactly nothing.

Once you subtract all of that, a "99.9% uptime guarantee" in practice covers unplanned hardware and hypervisor failures inside the host's own network, during periods they were not performing maintenance, that their own monitoring recorded. That is a much smaller promise than the badge on the pricing page suggests.

How much is an SLA credit worth in dollars?

Almost nothing, by design. Credits are calculated as a percentage of the monthly fee for the affected service, not as compensation for your losses, and most tiers cap out at 50-100% of one month.

Run the numbers on a real outage. Say your store goes down for two hours on a weekday.

Monthly plan costTypical credit tier for 2h outageCredit valueRevenue lost at $200/hrNet position
$9.99 shared10% of monthly fee$1.00$400-$399
$30 business10% of monthly fee$3.00$400-$397
$89 managed10% of monthly fee$8.90$400-$391
$300 enterprise VPS25% of monthly fee$75.00$400-$325

According to the Uptime Institute's 2024 Annual Outage Analysis, 54% of operators reported that their most recent significant outage cost more than $100,000 (2024). At the small business end the numbers are smaller but the ratio is identical: we broke down how website downtime costs $137 to $427 per minute for typical commercial sites. Two hours at the low end of that range is $16,440. The credit is $8.90.

And you have to ask for it. Nearly every SLA requires a written claim, submitted through a specific channel, within 15 to 30 days of the incident, including your own timestamps and evidence. Miss the window and the claim expires. Hosts do not proactively credit accounts, and a credit applied to next month's invoice is not money back in your pocket if you are planning to leave.

How to read a hosting SLA before you sign

Give it 20 minutes. You are looking for six things, and you can find all of them with ctrl+F.

  1. The measurement method. Search for "measured" or "monitoring." Internal-only measurement at five-minute intervals is a red flag. External, one-minute, multi-location is what you want.
  2. The exclusion list. Search for "excluded" or "shall not include." Count the categories. More than eight and the guarantee is decorative.
  3. The maintenance window policy. Search for "maintenance." How much notice, how often, is there a standing window, and is emergency maintenance capped at all?
  4. The credit schedule. Search for "credit." Find the actual percentage table and the cap. If the cap is one month's fee, that is your maximum exposure recovery.
  5. The claim procedure and deadline. Search for "claim" or "request." Note the channel, the deadline and what evidence you must supply.
  6. The termination right. Search for "terminate." Some SLAs let you exit without penalty after repeated breaches. That clause is worth more than the credits.

While you are in the contract, read the renewal terms too. A cheap first year with a guarantee you cannot enforce and a 200% price jump at month 13 is a common combination, and we mapped out why hosting bills double at renewal in detail.

One more thing to check that is not in the SLA at all: what the host does between the vulnerability disclosure and your patch. An SLA measures availability after something breaks. Virtual patching and network-level rules prevent the break. We wrote about how managed hosts handle WordPress zero-days because that work never shows up in an uptime percentage, and it is a better predictor of your actual downtime than three nines on a badge.

What a usable uptime guarantee looks like

A guarantee worth having is short, specific and readable in five minutes. It names the measurement method. It keeps the exclusion list to the genuinely unavoidable. It states the credit schedule in a table instead of a paragraph. And it does not hide behind a support queue that takes three days to acknowledge a claim.

Our service level agreement is published in full, and you can read it before you become a customer rather than after. A few things we hold ourselves to that differ from the industry template:

Monitoring runs 24/7 from outside our network, so the downtime record is not something we assemble after the fact from our own logs. Support responds in under 2 hours during business hours, which means an SLA claim gets a human reading it the same day rather than sitting in a ticket queue. TopSyde Sentinel watches for malware and code-level failures that do not register as downtime, because a site serving injected spam links returns a perfect 200 to every uptime checker.

Plans start at $89/mo per site. That is more than a $9.99 shared plan, and the difference is not the uptime badge. It is the absence of a forty-item exclusion list, infrastructure your developer will not fight with, and the fact that when something breaks you get a person instead of a credit form. If you want the technical specifics behind the guarantee, the hosting spec sheet lists the stack, and pricing shows what each tier includes.

Every plan comes with a 30-day money-back guarantee, and we handle migration. If you are currently on a host whose SLA you have never read, go read it this week. Then compare.

Frequently asked questions

Does 99.9% uptime mean my site is basically never down?

It means up to 43 minutes and 50 seconds of downtime per month is contractually acceptable, and that figure only counts outages that survive the exclusion list. Scheduled maintenance, DDoS events and anything the host classifies as customer-caused are typically subtracted before the calculation runs, so real-world downtime can exceed the allowance without triggering a breach.

Can I get cash instead of account credit for an SLA breach?

Almost never. Standard hosting SLAs limit remedies to service credit applied to future invoices, and most explicitly state that credits are the sole and exclusive remedy. A handful of enterprise contracts negotiated at volume include cash terms or early-termination rights, but on a standard plan the credit is the ceiling.

What if my site is up but broken, slow or serving spam?

Uptime monitors check that a server responds. They do not check that the response is correct. A site returning a 200 with a broken checkout, a 12-second load time or injected SEO spam counts as fully available under every SLA we have read. Content and behavior monitoring is a separate layer from availability monitoring.

How do I prove downtime happened if the host disputes it?

Run independent external monitoring and keep the logs. A third-party service with one-minute checks from multiple locations gives you timestamped evidence that does not come from the host's own dashboard. Submit that evidence with your written claim inside the deadline stated in the agreement, usually 15 to 30 days from the incident.

Marcus Webb
Marcus Webb

DevOps & Security Lead

12+ years DevOps, Linux & cloud infrastructure certified

Marcus leads infrastructure and security at TopSyde, managing the server fleet and AI monitoring systems that keep client sites fast and protected. Former sysadmin turned WordPress hosting specialist.

Related Articles

View all →

Free AI audit

Is your site actually fast?

Get a free homepage audit covering performance, SEO and usability, with a prioritized fix list. See the report on screen and get a copy by email. No account or payment required; allow a few minutes for the checks.

Free homepage report. No account or payment required.