Security
Backup and Recovery Overview
Backup scope, restore process, and recovery expectations for TrustRFP AI production deployments.
Backup scope
Production deployments should back up PostgreSQL records, object storage files, configuration metadata, and operational audit records needed to restore customer workspaces.
- PostgreSQL should use encrypted daily backups and point-in-time recovery where the managed database provider supports it.
- Object storage should use private buckets, encryption, lifecycle policies, and versioning where required by the customer agreement.
- Secrets should be restored from the deployment secret manager rather than from application backups.
Recovery practice
Recovery procedures should include database restore validation, object storage integrity checks, migration replay, smoke tests, and customer-impact review before returning traffic.
Recovery objectives
RPO and RTO are defined by plan or enterprise agreement. Enterprise private offers may include custom recovery objectives, region choices, and dedicated deployment terms.