At HR Instance, we recognize that human resource, attendance, and payroll records are mission-critical to your business operations. This Data Recovery Policy outlines our comprehensive backup architecture, disaster recovery protocols, Recovery Point Objectives (RPO), Recovery Time Objectives (RTO), and incident response mechanisms designed to safeguard your enterprise data against hardware failures, cyber threats, natural disasters, or accidental loss.
Continuous WAL transaction log replication
Full multi-zone container & database restore
Server-side encryption at rest & TLS 1.3 in transit
100% Indian data storage (ap-south-1)
1. Automated Backup Architecture
HR Instance employs a multi-tiered, automated backup architecture ensuring zero single-point-of-failure. All production databases and file assets are protected through continuous and point-in-time snapshot mechanisms:
PostgreSQL Write-Ahead Logging (WAL) is archived continuously, enabling point-in-time recovery (PITR) within minute-level precision.
Complete automated cryptographic database dumps executed every 24 hours at off-peak hours (02:00 AM IST) and stored in multi-zone object storage.
Long-term immutable archive snapshots retained for compliance, audit trails, and statutory payroll verification requirements.
2. Recovery Objectives (RPO & RTO)
We benchmark our resilience against industry-leading disaster recovery service level agreements:
- Recovery Point Objective (RPO) ≤ 1 Hour: Under severe failure conditions, maximum potential data divergence is bounded to no more than 60 minutes of transactional activity, with standard operational point-in-time recovery targeting under 15 minutes.
- Recovery Time Objective (RTO) ≤ 4 Hours: In the catastrophic event of a full server or multi-zone hardware failure, complete infrastructure reconstitution, database restoration, and application redeployment will be completed within 4 hours.
- Service Restart RTO ≤ 15 Minutes: For isolated worker node faults, automated PM2 cluster watchdogs and health probes trigger instance restarts and traffic re-routing within 15 minutes.
3. Per-Tenant Database Isolation & Granular Restores
Unlike shared single-database multi-tenant systems where restoring one client impacts all companies, HR Instance provisions an independent PostgreSQL database per customer (e.g., hrms_yourcompany).
Key Benefits of Tenant Isolation
- • Independent Rollback: If an administrator accidentally deletes critical employee records, their database can be restored to an earlier timestamp without affecting any other customer.
- • Zero Data Bleed: Restoration processes operate within strict per-tenant sandbox boundaries, eliminating cross-tenant contamination.
- • Instant Instance Re-provisioning: In the event of application container corruption, the application layer is re-cloned from template cache in under 60 seconds and reconnected to the recovered database.
4. Backup Security, Encryption & Storage
All backup archives are subject to the same rigorous enterprise security standards as live production data:
- AES-256 Encryption at Rest: All database dumps and file snapshots are encrypted before transfer using AES-256 cipher standards with rotated key management.
- TLS 1.3 Transport Security: Backup replication streams between application servers and secure storage tiers are conducted strictly over TLS 1.3 encrypted channels.
- Geographic Redundancy in India: All backup replicas are stored across physically separated AWS Mumbai Availability Zones (ap-south-1a, ap-south-1b, ap-south-1c). Your corporate data never leaves Indian territory.
- Immutable Storage (WORM): Production backup repositories are configured with Write Once, Read Many (WORM) policies to prevent ransomware tampering or malicious deletion.
5. Disaster Recovery Testing & Integrity Verification
Backups are only as reliable as their last successful restore. We conduct rigorous verification protocols:
- Automated Daily Checksum Verification: Backup creation pipelines automatically perform SHA-256 checksum validation and test integrity verification immediately upon snapshot completion.
- Weekly Automated Sandbox Restores: Randomly selected tenant database backups are automatically restored into ephemeral staging environments weekly to verify data consistency and migration health.
- Quarterly Full-Scale Disaster Drills: Engineering teams conduct simulated complete region/node failure drills to test DNS failover, template rebuilding, and manual override procedures.
6. Customer Data Recovery & Self-Service Export
We believe you should always maintain full ownership and access to your data:
- On-Demand Self-Service Export: Administrators can export all employee profiles, attendance logs, leave balances, and payroll reports in standard formats (CSV, Excel, JSON, PDF) directly from their instance dashboard at any time.
- Assisted Tenant Rollback: If an administrator requires a point-in-time rollback due to internal human error (e.g. erroneous bulk salary updates), our support team can execute an assisted restore upon authorized verification.
- Post-Termination Grace Period: Following subscription cancellation or expiration, all tenant data and corresponding backup archives are preserved for 30 days to allow complete final exports before permanent, irreversible zero-fill deletion.
7. Incident Escalation & Emergency Support
In the event of any service disruption or emergency recovery request, our team maintains 24/7 incident response readiness: