Network and Infrastructure Security

Backups and Restore Testing

Production data is backed up on a defined schedule under our backup policy, with point-in-time recovery for critical data. Backups are encrypted and held in a separate, access-controlled location from production, and for critical data in a geographically separate region. The restore process is performed and documented at least annually against our recovery objectives.

How it is checked

Restore is performed and documented annually, and the Disaster Recovery Plan is tested annually.

Framework requirements this speaks to

  • ISO 27001 A.8.13 (information backup)
  • ISO 27001 A.5.30 (ICT readiness for business continuity)
  • SOC 2 Availability

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.