Resilience

Backup and recovery runbook

A customer-owned recovery model with explicit evidence instead of assumed backups.

01

Recovery targets

Agree recovery point and recovery time targets for database, attachments, configuration and application releases.

02

Backup scope

Back up PostgreSQL, persistent file storage, secrets references and the configuration required to rebuild the service.

03

Encryption and access

Encrypt backups, separate backup credentials from runtime credentials and restrict restore permissions.

04

Restore testing

Run scheduled restore rehearsals into an isolated environment and record duration, integrity checks and findings.

05

Incident sequence

Contain access, preserve evidence, select a recovery point, restore, validate, communicate and document the decision trail.

06

Customer ownership

The final schedule, tools, retention and on-call ownership belong to the customer unless a signed service package states otherwise.