Backup Policy
Purpose
Section titled “Purpose”This policy outlines the backup procedures for critical data assets to ensure data integrity, availability, and recoverability in compliance with SOC2 requirements.
This policy applies to all data assets critical to the organization’s operations, including:
- Code repositories
- Customer files
- Building Knowledgebase Database
- Application Database
Asset-Specific Backup Procedures
Section titled “Asset-Specific Backup Procedures”Code Repositories
Section titled “Code Repositories”- Storage: GitHub
- Backup Procedure: Distributed version control through Git
- Retention: Full version history maintained in GitHub
- Recovery Process: Clone or pull from GitHub repository
Customer Files
Section titled “Customer Files”- Storage: Amazon S3
- Backup Procedure: Relies on S3’s built-in redundancy
- Retention: Follows S3 standard retention policies
- Recovery Process: Access files directly from S3
Building Knowledgebase Database
Section titled “Building Knowledgebase Database”- Storage:
- Snapshots stored in Amazon S3
- Running instances hosted on Fly
- Backup Procedure: Versioned snapshots stored in S3
- Retention: Follows S3 standard retention policies
- Recovery Process: Restore from S3 snapshot to Fly hosting using data pipeline tooling
Application Database
Section titled “Application Database”- Storage: Hosted on Fly
- Backup Procedure: Daily automated snapshots by Fly
- Update Procedure: Snapshots are manually created before each production deploy
- Retention: Retain daily snapshots for 7 days
- Recovery Process: Restore from Fly snapshot
Metabase Database
Section titled “Metabase Database”- Storage: Hosted on Fly
- Backup Procedure: Daily automated snapshots by Fly
- Retention: Retain daily snapshots for 7 days
- Recovery Process: Restore from Fly snapshot or regenerate from source
Backup Verification and Testing
Section titled “Backup Verification and Testing”- Annual backup restoration tests shall be conducted for each asset to ensure recoverability.
- Results of backup tests shall be documented and reviewed by the IT team.
Responsibilities
Section titled “Responsibilities”The IT team is responsible for:
- Monitoring the execution of automated backups
- Conducting and documenting backup verification tests
- Ensuring proper retention of backups
- Managing access controls to backup systems
- Reviewing backup policies and procedures annually
- Ensuring compliance with SOC2 requirements
Incident Response
Section titled “Incident Response”In the event of data loss or corruption:
- Immediately notify the IT team
- Initiate data recovery procedures as outlined for each asset
- Document the incident and recovery process
- Conduct a post-incident review to prevent future occurrences
Policy Review
Section titled “Policy Review”- This policy shall be reviewed annually and updated as necessary to reflect changes in technology, business processes, or regulatory requirements.
- Last reviewed/updated: 2026-08-27
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
