1. What this covers
Continuity is the plan for keeping the service running through a failure. Disaster recovery is the plan for bringing it back when something fails anyway. This page describes both, in the detail a firm needs to assess us without handing an attacker a map.
2. How the service is built
Production runs on enterprise grade Canadian cloud infrastructure across multiple availability zones, so the loss of a single zone does not take the service with it. Production is segmented from corporate and pre-production environments.
Customer data is encrypted in transit with current TLS and at rest with AES-256, and every firm is isolated from every other firm at the data layer. The Security Policy has the detail.
3. Backups
Backups are encrypted at rest and in transit, run on a regular cycle, and support a thirty day recovery window as described in Storage and Data Retention.
Backups are access controlled and used only to restore service. They are not a second copy for anyone to browse, and they are not used for analysis, training or support convenience.
Restores are tested periodically. A backup nobody has ever restored is a hope rather than a plan.
4. If a provider fails
We depend on a small number of suppliers, and we publish who they are by category in the Sub-processors list. For each one we know what breaks if it disappears and what the fallback is.
Where a dependency is not easily replaceable, we say so rather than implying a redundancy we do not have. A firm assessing us is entitled to know which of our suppliers would hurt most if they went down.
5. What we restore first
In a recovery the order is: authentication, then the case file and documents, then the forms and portals, then the assistant and the intelligence feeds. A practice can work from a case file. It cannot work from an analytics dashboard.
6. How you will hear about it
Incidents are posted on the Status page, and material disruption is emailed to account owners. We give advance notice of planned maintenance where it is practicable.
During a long outage we would rather post a short honest update every hour than one polished statement at the end.
7. What we do not publish yet
We do not publish a contractual recovery time objective or recovery point objective. We maintain documented plans aligned to internal recovery objectives, and we are not going to put a number on a public page that we cannot yet evidence with a third party audit.
We are also not SOC 2 certified yet, and we say so on the Security page rather than leaving it to be discovered. Firms with a formal vendor assessment can ask us for what we do have, in writing, at legal@thenovasystem.com.
8. Your own continuity
Your data is yours and you can export it at any time, as set out in Account Deletion and the Master Subscription Agreement. A firm that can export its records is a firm that is not trapped by anyone supplier problems, including ours. We think you should hold a recent export regardless of what any vendor tells you about their backups.