Skip to content

GoRefer Trust Center

Business Continuity & Disaster Recovery

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

GoRefer publishes business continuity and disaster recovery targets. The tables below describe what we plan for; how quickly we can actually recover depends on the services in use and on backups and restores that have been tested.

When you assess these targets, you can ask us for the current backup setup, the recovery runbook and the results of completed restore exercises. The targets are not measured recovery results or a contractual service guarantee.

99.9% uptime target
Backup details on request
Quarterly Test Target
Recovery Planning

Recovery Time Objective

< 4 hrs

For critical services

Recovery Point Objective

< 1 hr

Max data loss target

Backup Frequency

Scheduled

Current schedule on request

DR Test Cadence

Quarterly

Policy target; test records on request

Recovery Targets by Service

Updated September 2026

RPO (Recovery Point Objective) defines the maximum acceptable data loss — how far back in time we could recover to after an incident. RTO (Recovery Time Objective) defines the maximum time we target to restore service to operational status.

ServicePriorityRPORTORecovery Mechanism
API & Application
Critical< 1 hour< 4 hoursFailover and health checks: details on request
Primary Database
Critical< 1 hour< 2 hoursReplica sets and point-in-time recovery: details on request
File Storage
CriticalDepends on the storage service< 15 minutesDepends on the storage service and region
Email Delivery
ImportantN/A< 30 minutesQueued retry with exponential backoff; provider-level redundancy
AI Features (Gio)
ImportantN/A< 30 minutesMicrosoft Foundry, with Azure OpenAI as a fallback
Analytics & Reporting
Standard< 24 hours< 24 hoursRebuild from primary data store; non-critical path

Backup Architecture

Updated September 2026

Our backup plan covers the categories below. Current retention windows, encryption, location and restore coverage are available on request, along with the results of completed tests.

FrequencyWhat's Backed UpRetentionVerification Cadence
Continuous (oplog)Primary database — all write operationsUntil point-in-time window expiresMonthly restore-verification target
DailyFull database snapshotSet per backup policy; details on requestMonthly restore-verification target
WeeklyFull database snapshot + configuration state90 daysQuarterly restore-test target
MonthlyFull environment configuration snapshot12 monthsAnnual recovery-exercise target

Backup encryption and location

Ask us for the encryption, location and access settings of each backup store. Having backups does not by itself mean that recovery into another region is set up.

Disaster Recovery Plan

Updated September 2026

Incident Classification

  • Tier 1 — Total service loss

    All production services unreachable. Immediate DR activation. RTO target: 4 hours.

  • Tier 2 — Partial service degradation

    One or more services impaired. Targeted recovery. RTO target: 2 hours.

  • Tier 3 — Data integrity concern

    Potential data corruption or loss. Recovery initiated from last verified clean backup.

  • Tier 4 — Single-component failure

    Isolated component failure with automatic failover. Usually transparent to users.

Recovery Procedures

  • Runbooks maintained and version-controlled

    Step-by-step recovery procedures are documented and updated after each DR exercise

  • On-call rotation

    Current on-call coverage and escalation for critical incidents: details on request

  • Communication plan

    Policy target: notify affected customers within 1 hour of a Tier 1/2 declaration, subject to incident assessment

  • Post-incident review

    Policy target: complete a post-mortem within 5 business days and retain the review

DR Testing Program

Updated September 2026

Our exercise targets are listed below. Records of completed tests, their findings and follow-up work are available on request.

Monthly

  • Automated database restore verification

  • Backup integrity validation

  • Monitoring alert simulation

Quarterly

  • Full recovery drill from snapshot

  • Failover simulation for critical services

  • Runbook review and update

Annual

  • Full disaster recovery exercise (Tier 1 scenario)

  • Business continuity plan review

  • External review of DR posture