GoRefer Trust Center
Business Continuity & Disaster Recovery
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer publishes business continuity and disaster recovery targets. The tables below describe what we plan for; how quickly we can actually recover depends on the services in use and on backups and restores that have been tested.
When you assess these targets, you can ask us for the current backup setup, the recovery runbook and the results of completed restore exercises. The targets are not measured recovery results or a contractual service guarantee.
Recovery Time Objective
< 4 hrs
For critical services
Recovery Point Objective
< 1 hr
Max data loss target
Backup Frequency
Scheduled
Current schedule on request
DR Test Cadence
Quarterly
Policy target; test records on request
Recovery Targets by Service
Updated September 2026
RPO (Recovery Point Objective) defines the maximum acceptable data loss — how far back in time we could recover to after an incident. RTO (Recovery Time Objective) defines the maximum time we target to restore service to operational status.
| Service | Priority | RPO | RTO | Recovery Mechanism |
|---|---|---|---|---|
API & Application | Critical | < 1 hour | < 4 hours | Failover and health checks: details on request |
Primary Database | Critical | < 1 hour | < 2 hours | Replica sets and point-in-time recovery: details on request |
File Storage | Critical | Depends on the storage service | < 15 minutes | Depends on the storage service and region |
Email Delivery | Important | N/A | < 30 minutes | Queued retry with exponential backoff; provider-level redundancy |
AI Features (Gio) | Important | N/A | < 30 minutes | Microsoft Foundry, with Azure OpenAI as a fallback |
Analytics & Reporting | Standard | < 24 hours | < 24 hours | Rebuild from primary data store; non-critical path |
Backup Architecture
Updated September 2026
Our backup plan covers the categories below. Current retention windows, encryption, location and restore coverage are available on request, along with the results of completed tests.
| Frequency | What's Backed Up | Retention | Verification Cadence |
|---|---|---|---|
| Continuous (oplog) | Primary database — all write operations | Until point-in-time window expires | Monthly restore-verification target |
| Daily | Full database snapshot | Set per backup policy; details on request | Monthly restore-verification target |
| Weekly | Full database snapshot + configuration state | 90 days | Quarterly restore-test target |
| Monthly | Full environment configuration snapshot | 12 months | Annual recovery-exercise target |
Backup encryption and location
Ask us for the encryption, location and access settings of each backup store. Having backups does not by itself mean that recovery into another region is set up.
Disaster Recovery Plan
Updated September 2026
Incident Classification
Tier 1 — Total service loss
All production services unreachable. Immediate DR activation. RTO target: 4 hours.
Tier 2 — Partial service degradation
One or more services impaired. Targeted recovery. RTO target: 2 hours.
Tier 3 — Data integrity concern
Potential data corruption or loss. Recovery initiated from last verified clean backup.
Tier 4 — Single-component failure
Isolated component failure with automatic failover. Usually transparent to users.
Recovery Procedures
Runbooks maintained and version-controlled
Step-by-step recovery procedures are documented and updated after each DR exercise
On-call rotation
Current on-call coverage and escalation for critical incidents: details on request
Communication plan
Policy target: notify affected customers within 1 hour of a Tier 1/2 declaration, subject to incident assessment
Post-incident review
Policy target: complete a post-mortem within 5 business days and retain the review
DR Testing Program
Updated September 2026
Our exercise targets are listed below. Records of completed tests, their findings and follow-up work are available on request.
Monthly
Automated database restore verification
Backup integrity validation
Monitoring alert simulation
Quarterly
Full recovery drill from snapshot
Failover simulation for critical services
Runbook review and update
Annual
Full disaster recovery exercise (Tier 1 scenario)
Business continuity plan review
External review of DR posture