Security

Backup and Recovery Overview

Backup scope, restore process, and recovery expectations for TrustRFP AI production deployments.

Backup scope

Production deployments should back up PostgreSQL records, object storage files, configuration metadata, and operational audit records needed to restore customer workspaces.

  • PostgreSQL should use encrypted daily backups and point-in-time recovery where the managed database provider supports it.
  • Object storage should use private buckets, encryption, lifecycle policies, and versioning where required by the customer agreement.
  • Secrets should be restored from the deployment secret manager rather than from application backups.

Recovery practice

Recovery procedures should include database restore validation, object storage integrity checks, migration replay, smoke tests, and customer-impact review before returning traffic.

Recovery objectives

RPO and RTO are defined by plan or enterprise agreement. Enterprise private offers may include custom recovery objectives, region choices, and dedicated deployment terms.