infrastructureVersion 1SOC2ISO27001NIST800-171
Backup & Recovery Policy
Backup configurations and restoration targets (RPO/RTO) for every data class.
Backup & Recovery Policy
1. Purpose
Ensures Rex Black can restore the confidentiality, integrity, and availability of its data following accidental deletion, corruption, ransomware, or regional AWS failure.
2. Scope
Every production data store: DynamoDB tables, S3 buckets, SSM parameters, KMS keys, source code repositories, and configuration state.
3. Policy statements
3.1 DynamoDB
- Every production DynamoDB table has Point-In-Time Recovery (PITR) enabled. This provides continuous backups for the last 35 days.
- Before any destructive schema migration, a manual on-demand backup is taken and retained for 7 days.
- Deletion of a DynamoDB table requires Security Officer approval.
3.2 S3
- All production S3 buckets have versioning enabled.
- Buckets holding legally binding records (e.g.,
rexblack-executed- documents) additionally have Object Lock in COMPLIANCE mode. - Lifecycle rules transition non-current versions to Glacier Deep Archive after 90 days and delete after 7 years, unless the bucket is under Object Lock retention (which supersedes deletion).
3.3 Source code and config
- GitHub is the system of record for source code; a mirrored backup is pulled nightly by a Lambda into an S3 bucket and retained for 90 days.
- SST/Pulumi state is stored in an S3 backend with versioning.
3.4 Cross-region resilience
- S3 buckets marked
criticality: criticalare replicated tous-west-2via Cross-Region Replication. - DynamoDB tables marked
criticality: criticaluse Global Tables acrossus-east-1andus-west-2.
3.5 Restoration testing
- A quarterly restore drill exercises:
- A full DynamoDB PITR restore into a sandbox.
- Retrieval of an archived S3 object (including Object Lock).
- Recovery of a GitHub repository from the nightly mirror.
- Each drill is logged under
compliance/bcp-drills/YYYY-MM-DD.mdwith the RTO/RPO observed.
3.6 Targets
| Asset class | RPO | RTO |
|---|---|---|
| Production DynamoDB | ≤ 5 min | ≤ 4 hr |
| Production S3 | ≤ 15 min | ≤ 4 hr |
| Executed legal records | 0 | ≤ 24 hr |
| Source code & infra | ≤ 24 hr | ≤ 24 hr |
4. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Engineering lead | Implements and monitors backup jobs. |
| Security Officer | Reviews quarterly drill results; approves exceptions. |
| CEO | Authorizes BCP invocation during a declared disaster. |
5. Enforcement & exceptions
Production resources without backups configured are blocked from receiving customer traffic. Exceptions require Security Officer approval and a compensating control (e.g., the data is derived and can be re-materialized).
6. References
006-business-continuity-and-disaster-recovery-plan.md010-data-retention-and-disposal-policy.mdregisters/incident-response-runbook.md
7. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.