Trust centre

Every promise here has a number and a way to check it.

We target 99.5 percent provisioning success. Anything that fails is refunded automatically inside 60 seconds. Any incident over 30 minutes gets a published post mortem within 72 hours. Eight transparency commitments sit below, and each one can be verified from outside this company without asking us for anything.

Search any large travel eSIM brand and the autocomplete offers you the word scam. That is the market we sell into, so trust is not a values slide here. It is the product.

The targets, and what happens when we miss

What we measureTargetWhat happens when we miss it
Provisioning success99.5 percent of paid ordersAutomatic refund inside 60 seconds, no ticket
First support responseUnder 60 seconds, 24 hours a dayThe queue is published on the status page and staffing moves
Incident notificationAffected customers told before they noticeCredit applied without a request, and named in the post mortem
Post mortem publicationWithin 72 hours for anything over 30 minutesThe delay itself is published, with the reason
Coverage sample floorNo published figure under 25 samplesThe cell shows no data rather than a guess
Price drop protection30 days from purchaseThe difference is credited to the wallet automatically

Each row states a target we can miss. A target nobody can miss is decoration.

Why the target is not one hundred percent

Because one hundred percent is a lie in any system with a network in it, and a target nobody can miss is a target nobody manages.

Publishing 99.5 percent is an admission that in every thousand orders, roughly five will fail somewhere between the payment and the profile. The useful question is what happens to those five people.

The answer is that the refund fires before they have finished being annoyed. The system detects the failure, reverses the charge inside 60 seconds, and sends a message explaining what happened and what to do instead.

The customer does not open a ticket. Nobody has to decide whether they deserve it. That path is engineered with the same care as the happy one, because it is the path that generates every review we will ever be judged on.

Incident policy

The uncomfortable part is the second step. Moving the status page before we know the cause means publishing our own bad news while it is still confusing, and it means a journalist can quote a timestamp back at us.

We do it because the alternative is a customer in an airport discovering the outage themselves, which is how a technical problem becomes a reputational one.

  • Detection, mostly automated, from provisioning success rates rather than from a person noticing
  • The status page component moves within five minutes of the incident being declared, before we know the cause
  • Affected customers are identified and contacted, with a credit already applied where service was degraded
  • An incident commander runs the response and a separate person handles communications, so neither job starves the other
  • Anything over 30 minutes gets a written post mortem published within 72 hours
  • The post mortem names systems and decisions rather than individual employees, and every fix carries an owner and a date
Real trafficnever a speed test
Coarse locationabout one kilometre
Aggregatednothing under 25 samples
Publishedwith the sample count
A synthetic speed test would spend your data to tell us something we can measure for free.
How a measurement becomes a published number, with the sample floor in the middle.

The eight transparency commitments

Every one of these is uncomfortable and every one is checkable without our help. Open a plan in the store and look for the throttle number. Open a coverage page and look for the sample count. Open the pricing page and look for the comparison rows where a rival wins.

If any of those checks fails, the commitment is broken, and we would rather hear about it from you than not at all.

  • We publish the throttle threshold as a number, on the buy button, on every plan
  • We publish measured speeds with sample sizes, including the ones that make us look bad
  • We publish a quality tier for every country and we label our weak markets honestly
  • We publish a post mortem for every incident over 30 minutes, within 72 hours
  • We tell affected customers before they discover a problem themselves
  • We publish a transparency report twice a year, including when every number in it is zero
  • We refuse the sale in territories our partners cannot serve rather than refunding later

Where we lose

We are at 145 destinations and Airalo reaches 169 on its global plan. Saily bundles ad blocking that was audited at 28.6 percent data saved, and we have no equivalent feature. On a single small purchase we are frequently beaten on headline price. All three of those are on our own comparison pages, written by us, because a trust centre that only lists strengths is an advertisement.

Where to check each thing yourself

PageWhat is on itWhat it lets you verify
StatusLive component state, incident history, every post mortemThat we publish our own bad news on time
SecurityPasswordless sign in, passkeys, sessions, disclosure contactThat no card data sits on our systems
Privacy policyWhat we collect, where it lives, your rightsThat the coverage dataset is anonymous by design
Transparency reportLaw enforcement requests, data requests, deletionsThat we publish at zero rather than only when it suits
AccessibilityThe standard we target and the gaps we have not closedThat the statement names known failures
Refund policyThe automatic refund rule and the fair use numberThat the plain language summary matches the terms

Nothing in this table needs our permission or our help. That is the test of whether a trust page means anything.

Questions people actually ask

What is your uptime target?
99.5 percent provisioning success. We state it as provisioning success rather than uptime because a website that loads while a profile fails to install is not up in any sense that matters to a traveller. The measure is the share of paid orders that reach a working profile.
What happens when provisioning fails anyway?
The refund is issued by the system within 60 seconds. No ticket, no form, no conversation. That is the point of publishing a target below one hundred percent, that the failure path is designed rather than improvised.
When do you publish a post mortem?
For any incident lasting more than 30 minutes, within 72 hours, on the status page. It names the systems, the timeline, the customer impact and the fixes with owners. It does not name individual employees.
Do you tell customers before they notice?
That is the commitment. If we can identify who is affected, we contact them and credit them before they contact us. It is uncomfortable because it means we generate our own bad news on the record with a timestamp.
How do I know your coverage numbers are not marketing?
Because they come from real customer traffic rather than synthetic speed tests, they are never published for a cell with fewer than 25 samples, and every country page shows the sample count alongside the median and the slowest tenth. Unflattering countries are published with the same method as flattering ones.
What do you do with my data?
We sell you data and connect you, and not much else. Coverage measurements are anonymous, carry a coarse location of roughly one kilometre, and can be switched off in one tap. We do not sell personal data. The privacy policy has the full detail and the security page has the design.
Where can I check all of this myself?
The status page for live component state and incident history, the security page for account protection and disclosure, the privacy policy for data handling, and the transparency report twice a year for law enforcement and data request numbers.