No accepted write is ever lost
Acknowledged writes are fsynced before ack and persisted to two dedicated clouds.
Writes degrade last
Under sustained extreme overload, at most ~10% of new writes may be deferred — always with explicit retry signals (429/503 + Retry-After). Never silent.
Overload sheds, it doesn't crash
Overload shedding is deliberate and memory-guarded, never a crash: zero crashes across all stress scenarios; recovery within seconds of load subsiding.
Fast in normal operation
Reads, writes and entity lookups stay fast — measured under production-shaped stress.
Search that stays quick
Vector search stays quick on typical routes; version-heavy routes (30k+ versions) may take seconds — rare, and version pruning keeps routes lean.
One SLO for every tier
The same contract on every tier, including Free. No tier-gated availability.