Business Continuity and Incident Response Plan
1. Recovery Objectives (RTO & RPO)
To ensure system reliability, Safe defines clear recovery targets for technical or infrastructure failures. These indicators allow the client’s IT team to plan their operational tolerance.
| Service | Disruption Scenario | RPO (Recovery Point) | RTO (Recovery Time) | Priority |
|---|---|---|---|---|
| Database (SQL) | Instance or zone failure | 1 hour | 5 minutes | High |
| AI Engine | Freeze or high load | Immediate | 30 minutes | Medium |
| Storage | Local hardware failure | 5 minutes | 5 minutes | High |
| Web App | Deployment error | N/A | 5 minutes | High |
Note: In Full On-Premise deployments, these metrics depend on the client’s hardware infrastructure and local backups.
2. Incident and Security Breach Management
Safe has an Equipo de Respuesta ante Incidentes (IRT) led by its CTO and Head of Product, responsible for executing the emergency protocols.
2.1. Severity Classification
• Level 1 (Critical):
Negative impact on reputation, client reaction or leakage of sensitive data.
• Level 2 (Major):
Significant disruption to operations; data leakage limited to public information.
• Level 3 (Limited):
Minor disruption with no impact on data security.
2.2. Response Protocol
• Identification:
Detection of abnormal behaviour, system errors or unauthorised access attempts.
• Containment:
Logical or physical isolation of the affected resources to prevent the incident from spreading.
• Investigation:
Forensic analysis using snapshot backups to determine the root cause
• Recovery:
Restoration of systems to their secure state and updating of security controls.
3. Backup and Disaster Recovery (DR) Strategy
Data integrity is protected through a multi-zone redundancy strategy.
• Cloud (SaaS/Hybrid):
Databases and media files have synchronous replication to persistent disks.
• On-Premises:
The system persists logs and critical configuration data locally. Integration with the client’s backup system or the use of hardware redundancy through mirrored NVMe disks is recommended.
• DR Testing:
An annual disaster simulation test is carried out to validate the adequacy of the procedures and the recovery KPIs.
4. Deployment and Maintenance Models
Safe offers full flexibility in how the system is installed and maintained, allowing the client to choose the desired level of control.
| Feature | Remote Configuration | On-Site Installation |
|---|---|---|
| Installation | Performed via SSH or secure VPN by the Safe team. | Carried out at the client’s premises with phone supervision. |
| Updates | Security patches and major versions managed by Safe. | Scripts and packages provided for execution by the client. On-site visit for major updates (optional). |
| Maintenance | Periodic monitoring and incident handling included (optional). | Technical support available; servers maintained by the client. |
| Advantage | Lower operational load for the client’s IT team. | Full control and absolute sovereignty over physical access. |
Regardless of the model, Safe guarantees that major version updates are tested in staging environments before moving to production.
Contact and Support
For technical enquiries about hardware compatibility or custom quotes, contact us at:
• Technical Support: support@safe.ai
• Sales: commercial@safe.ai
