What we commit to
- An immutability lock cannot be shortened from the console, by you or by us.
- Residency is confirmed before the first capture, in the region you select.
- Every destruction closes with a signed certificate that outlives the data.
The security model in plain language: what is immutable, where data lives, and how destruction is proven.
rp-2026-08-05T02:00:14Z-9f42c81a
An insurer asks how recovery is proven. A regulator asks where the data sits. A prospect’s questionnaire runs to forty questions. Your vendor’s assurance is not an answer you can forward, so the answering falls to you, on a Friday, in your own words.
Assurance is not evidence
A vendor promising that backups are safe gives you nothing to put in front of an auditor.
Compromise reaches the backups
An attacker with administrator access goes after the recovery points first, because that is what forces the payment.
Deletion has to be provable
When a client offboards, saying the data is gone is not the same as showing it.
When a client offboards, saying the data is gone is not the same as showing it.
Immutability by default
Recovery points carry rolling locks that renew daily. Suspension for non-payment leaves existing immutability intact, so a commercial dispute stays a commercial dispute.
Residency as a boundary
Each organization chooses its storage location from your allowed set; a residency preflight confirms the region before the first capture.
Certified destruction
When retention ends and destruction runs, a signed certificate is issued. It outlives the data it certifies.
Read-only by design
Backups run under a consented read-only identity; writes exist only during restores, just-in-time, and revoke themselves.
The next security review is coming. Walk through the console and leave with the artifacts your clients keep asking for. The questionnaire becomes an hour’s work.
Leave with the artifacts your clients keep asking for.