// scope
This is the baseline BCDR posture for services we operate under a signed MSA + SoW. The exact tier (Standard, Business, Sovereign) for your engagement is set in your SoW and the SLA. Sovereign customers may have a customer-specific BCDR addendum.
Last updated: August 16, 2026
1. Scope
This plan covers the infrastructure and applications we operate on your behalf under an SoW (private-LLM endpoints, agent runtimes, hosted apps, databases, and supporting systems). It does not cover the systems you operate yourself, even if we helped you build them Those are governed by your own BCDR plan.
2. Service tiers and recovery objectives
We operate each engagement to one of three tiers, named in the SoW:
- Standard. Single-region, daily backups, manual failover. Suitable for non-critical or dev/test workloads.
- Business. Multi-AZ within a region, 1-hour backups, automated failover for stateless services, RPO 1 hour, RTO 4 hours.
- Sovereign. Multi-region with hot standby, continuous backup (point-in-time recovery), automated failover for stateless services and orchestrated failover for stateful services, RPO 15 minutes, RTO 1 hour.
3. Backup strategy
- Frequency. Continuous (≤15 min) for Sovereign; hourly for Business; daily for Standard.
- Retention. 30 days online, 1 year archive, 7 years for compliance-tagged data (per the regulatory coverage addendum).
- Encryption. AES-256 at rest, with keys managed in a customer-scoped KMS where Sovereign customers require it (BYOK available).
- Integrity. Backups are checksummed and restore-tested on a rolling schedule; failures generate tickets.
- Storage separation. Backups are stored in a different region and a different cloud account from the primary. We do not rely on the same control plane for backups and primary.
4. Failover and high availability
- Stateless services. Run on at least two replicas across distinct availability zones; load balancer removes unhealthy replicas.
- Databases. Synchronous replica within the primary region (Business) and asynchronous replica in a secondary region (Sovereign); automated promotion in the secondary for stateless services, orchestrated promotion for stateful.
- Object storage. Cross-region replication with versioning and object-lock (where immutability is required).
- Networking. BGP-routed anycast IPs for customer-facing endpoints (Sovereign); health-checked DNS failover (Business).
- Secrets. Replicated to the secondary region before the failover runbook considers the system ready.
5. Disaster recovery testing
| Tier | Test type | Cadence | Documented as |
|---|---|---|---|
| Standard | Restore-from-backup | Quarterly | Internal record |
| Business | AZ failover + restore-from-backup | Quarterly + annually | Internal record + customer summary on request |
| Sovereign | Region failover (full DR test) | Quarterly (game day) | Joint runbook with customer, signed attestation |
DR tests include a customer communication test (we email you as if it were real and you confirm receipt), a recovery validation (checksums, smoke tests), and a post-test debrief with action items.
6. People and process
- On-call rotation staffed 24/7 for Sovereign, during Business Hours + on-call for Business, during Business Hours for Standard.
- Incident command system (ICS) used for any Sev-1 / Sev-2.
- Runbooks maintained in version control, peer-reviewed, and tested.
- Post-incident review (PIR) within 5 business days of any Sev-1; root cause shared with affected customers.
7. Communication during an incident
We communicate during an incident as follows:
- Status page. Live updates at status.empowered.guru (or a dedicated URL for Sovereign) within 15 minutes of incident detection.
- Customer email. Notification to the contact on file within 60 minutes for Sev-1, 4 hours for Sev-2, next business day for Sev-3.
- Incident bridge. A conference bridge is opened for Sovereign customers on Sev-1 within 30 minutes; Business customers on request; Standard customers receive written updates only.
- After the incident. Written post-incident report (PIR) within 5 business days for Sev-1, 10 business days for Sev-2.
See our incident-response page for the notification commitments when the incident involves personal data.
8. Ransomware posture
- Backups are immutable and air-gapped from the primary control plane.
- Restore tests confirm recovery from a worst-case scenario (full encryption of primary, no access to production keys).
- We do not pay ransoms; we restore from backup. This is a written policy, not a position.
- Customer-facing comms during a ransomware event are coordinated with the customer's counsel and, where required, law enforcement.
9. Vendor and subprocessor resilience
Each subprocessor we rely on for BCDR is itself documented at /legal/subprocessors. For critical dependencies we (a) maintain a documented exit plan, (b) test the alternative path annually, and (c) hold the alternative contractually ready where it is reasonable to do so.
10. RTO / RPO by tier
| Tier | RPO | RTO | Backup frequency | Failover type |
|---|---|---|---|---|
| Standard | 24 h | 24 h | Daily | Manual |
| Business | 1 h | 4 h | Hourly | Automated for stateless, manual for stateful |
| Sovereign | 15 min | 1 h | Continuous (≤15 min) | Automated for stateless, orchestrated for stateful |
11. Changes
We review this plan quarterly and after any Sev-1. Material changes are communicated to active clients.
12. Contact
Operations: ops@empowered.guru. Incidents: security@empowered.guru.
