Business Continuity & Disaster Recovery Policy¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Classification | Internal (shareable under NDA) |
| Version | 1.0 |
| Effective date | 2026-06-11 |
| Next review | 2027-06-11 |
1. Purpose¶
Ensure critical services can be recovered and continued in the event of a disruption.
2. Backup & recovery¶
- Critical data is hosted on managed PostgreSQL (Supabase) with automated daily backups and point-in-time recovery (PITR), enabling restoration to a recent consistent state.
- Backups are managed by the provider with retention per plan.
- Restore capability will be validated through a documented restore test. (Restore test planned as part of the BCDR program.)
3. Recovery objectives¶
Target recovery objectives (to be confirmed by a formal Business Impact Analysis):
| Objective | Target |
|---|---|
| RPO (max data loss) | ≤ 24 hours (improved by PITR) |
| RTO (max downtime) | ≤ 24 hours (interim target; to be confirmed by the BIA) |
4. Business Impact Analysis¶
A formal Business Impact Analysis (critical functions, RTO/RPO/MAO/SDO, and impacts) has not yet been completed and is planned. (Planned — tracked in the BCDR task.)
5. Disaster recovery testing¶
A documented DR plan with at-least-annual DR testing against RTO/RPO is being established. (Planned.) Test results (date, scope, outcome) are recorded.
6. Redundancy¶
Critical data services run on managed cloud infrastructure with multi-availability-zone redundancy; hosting and networking redundancy is provided at the cloud-provider level.
Revision history¶
| Version | Date | Author | Change | Approved by |
|---|---|---|---|---|
| 1.0 | 2026-06-11 | Puneet Gupta | Initial draft | Puneet Gupta (Co-Founder) |