GoRefer Trust Center
Infrastructure
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer uses MongoDB and AWS services for storage and delivery. This page describes how the application is built; details of how each hosting provider is set up are available on request.
AWS Cloud Hosting
Updated September 2026
GoRefer uses AWS services, including S3 storage and email delivery. Hosting regions, server setup and each provider's security reports vary by service; ask us for current details rather than assuming them.
Compute & Networking
Compute services and containers: details on request
Hosting region and data location for each service: details on request
Load-balancer health checks and failover: details on request
Network placement of our servers: details on request
Firewall rules and open inbound ports: details on request
Storage
File storage on Amazon S3 where it is enabled
Private files are shared through signed links; public assets follow different rules
How long a signed link stays valid depends on the feature that creates it
Storage transport and public-access rules: details on request
File versioning: details on request
Database — MongoDB Atlas
Updated September 2026
GoRefer uses MongoDB, with one database for platform records and a separate database for each firm. MongoDB Atlas can provide replication, backups and point-in-time recovery; which of these are turned on depends on the plan and settings in use.
Database Architecture
Each firm's records live in their own database; platform records use a separate one
Replica placement and failover: details on request
Database connection encryption (TLS): details on request
Database network-access policy: details on request
Atlas Security Controls
Allowed networks and private connections: details on request
Credential-rotation policy and recent rotations: details on request
Storage encryption and key management: details on request
MongoDB's current security and compliance reports: on request
Data-processing and transfer terms: on request
Availability Targets
Updated September 2026
We target 99.9% monthly uptime. This is an operational target, not a contractual service level agreement — see the Terms of Service for the availability commitment that applies to your subscription. Check your agreement for maintenance notice periods and any service-specific commitments.
| Service Component | Target Uptime | Failover Mechanism |
|---|---|---|
| API Server | 99.9% | Depends on the load balancer and available servers |
| Primary Database (managed) | 99.95% | Depends on the database setup |
| File Storage (cloud object store) | 99.99% | Depends on the storage service and region |
| Email Delivery | 99.9% | Delivery retries and provider availability |
| Edge Network / DNS | 99.99% | Depends on the DNS and edge provider |
Backups & Disaster Recovery
Updated September 2026
Backup Strategy
Point-in-time recovery
Depends on the database backup settings; ask us for the current recovery window
Database backups
Backup retention is an operational setting; ask us for the current policy
Snapshot retention
Daily, weekly and monthly retention windows: details on request
File versioning
Recovering an earlier version depends on the storage settings and the feature involved
Backup encryption
Encryption, location and access for backups: details on request
Recovery Objectives & Testing
RTO (Recovery Time Objective): 4 hours
Target time to restore full service from a complete infrastructure failure
RPO (Recovery Point Objective): 1 hour
Maximum acceptable data loss window in a catastrophic failure scenario
Monthly restore-verification target
Policy target: test a restore each month and keep the results
Quarterly recovery-exercise target
Policy target: conduct quarterly exercises and document results
Recovery runbook
Current recovery procedures and post-exercise reviews: available on request
For full RPO/RTO tables and DR plan details, see Business Continuity & Disaster Recovery.
Edge Network & DDoS Mitigation
Updated September 2026
Edge Security
DNS and edge provider setup and failover: details on request
Network and application DDoS protections in use: details on request
Web application firewall rules and exceptions: details on request
The application's own rate limits are separate from any limits at the network edge
Bot management and challenges: details on request
Monitoring Stack
Application error and performance monitoring
Error reports are filtered to reduce the personal data they carry; details on request
Monitoring intervals and on-call alerting: details on request
Database metrics and alert policies: details on request
Response coverage: details on request; incident targets are published on the Incident Response page