where the model stops being true
What the model assumes, and where those assumptions end.
A durability figure is only as good as the assumptions under it. Ours are printed here, in full, so you can decide for yourself whether they hold for your data. No other storage vendor publishes this section.
Correlated failure is not in the model
The recurrence treats provider failures as independent. Real ones sometimes are not — shared facilities, a common software version, or an economic shock can take several providers together. Diversity of the provider set is what limits this, not the arithmetic, and the arithmetic will not warn you when it stops holding.
Shards share a contract pool
Placement draws from one pool of host contracts rather than a pool per customer, so a single contract can hold shards belonging to many objects and many customers. A contract failure is therefore a small loss spread wide rather than a total loss for one object — but it means object outcomes are not fully independent of one another either.
Repair has to outrun loss, and it is measured doing it
Eleven nines is the line the repair cycle drives toward and re-checks every 48 hours, so between recomputes the figure is a forecast rather than a reading. The forecast is only as good as available repair capacity: if there were no healthier providers to move a shard to, the real number would sit below the line until there were.
Re-verified every cycle, not modeled once a year
The figure covers the next 360 hours because that is the window the repair cycle can hold and re-check against live data. An annual durability number is a projection made once and carried for twelve months; this one is recomputed from each provider's current measured history 24 times inside that same year. Two different quantities — ours is the one that gets tested.
The horizon is set by what the data supports. At 80+40, holding the line over a full year would require every provider to carry 8.7 years of measured remaining life expectancy. Over 15 days it requires 130 days — a threshold real providers meet, which is why the figure is re-established rather than assumed.
Independent review: none yet. The model, the parameters and the code that runs them have not been audited by an outside party. When that changes this page will say who did it and link what they published. Until then, the derivation above is the whole basis for the claim, which is exactly why it is printed here instead of summarized.