Trust and vendor file Business continuity

Business continuity

Last reviewed: [DATE]

This document describes how Innorve Academy stays available, how data is backed up and recovered, and what happens if a dependency fails.

How critical is this service?

Innorve Academy is a training platform. It is not member-facing and does not connect to the credit union's core or any other system. If it is unavailable, training and pilot record-keeping pause, but no member service is affected. Each credit union decides how to classify the service under its own policy.

Provider resilience

Innorve runs on managed cloud services rather than its own servers.

Component Provider Resilience notes
Web application Vercel Serverless functions in a US region [VERCEL REGION]. Static assets are served from Vercel's network. Vercel manages the underlying infrastructure.
Database and authentication Supabase on AWS Managed PostgreSQL in a US region [SUPABASE REGION]. Supabase manages the database server, patching and backups.
Email (sign-in and notifications) Planned: Resend [CONFIRM before first pilot] See "Dependency on email for sign-in" below

The database runs in a single region. Innorve has not configured a standby database in a second region. [CONFIRM] Each provider's own status page and resilience commitments apply.

Backups

  • Automated daily database backups, kept for 7 days. This requires the Supabase Pro plan. [CONFIRM plan before first pilot]
  • Backups are managed and encrypted by the provider.
  • Point-in-time recovery is not enabled. [CONFIRM]
  • Deleted data can remain in backups until they rotate out, up to 7 days.
  • Application code is kept in a private GitHub repository and can be redeployed from there. Database structure and rules are kept as versioned migrations in the same repository.
  • Restore testing: [CONFIRM: a restore test must be completed before the first pilot, and at least yearly after that].

Recovery targets

These are targets, not tested results. [CONFIRM]

Target Value Basis
Recovery point objective (RPO): maximum data loss [RPO] (proposed: up to 24 hours) [CONFIRM] Daily backups
Recovery time objective (RTO): time to restore service [RTO] (proposed: 1 business day) [CONFIRM] Restore from backup and redeploy from the repository

Scenarios

Scenario Effect Response
Vercel outage Website and platform unavailable; data unaffected Wait for provider recovery. Keep credit-union contacts informed. Redeploying to another host is possible from the repository but not pre-built. [CONFIRM]
Supabase outage Platform unavailable or read-only; sign-in fails Wait for provider recovery. Keep contacts informed.
Data corruption or accidental change Records wrong or missing Restore from the most recent good daily backup, within the 7-day window. Submitted work and released assessments are immutable, which limits accidental change.
Email provider outage New sign-ins fail See below
Loss of a key person at Innorve Slower support and recovery Named backup for each incident role. Provider accounts are held by more than one person. [CONFIRM]
Innorve ceases operation Service ends Credit unions can export CSV records at any time. [CONFIRM: notice period and data return terms for this event in the SOW]

Dependency on email for sign-in

Sign-in is passwordless. Every new sign-in needs an email: a one-time link or a 6-digit code. If email delivery fails, users who are not already signed in cannot sign in.

What still works:

  • users with an active session can keep working until their session expires [CONFIRM session lifetime];
  • the credit union's facilitators can run sessions with offline materials. [CONFIRM]

Fallback plan:

  1. Confirm the problem is with the email provider, not the credit union's mail filtering. Credit unions should allow-list the sending domain in advance. [CONFIRM sending domain]
  2. Switch the authentication service to a standby email provider. [CONFIRM: standby provider configured and tested]
  3. Tell affected credit-union contacts, and extend any activity deadlines that fall during the outage.

Credit-union mail filtering is a common cause of failed sign-in. Innorve will give each credit union the sending domain and addresses to allow-list before the pilot starts. [CONFIRM]

Communication during an outage

  • Innorve notifies each credit union's named contact of any outage that lasts longer than [CONFIRM] hours.
  • Status updates go to the same contacts until service is restored.
  • If an outage is caused by a security incident, the incident response plan applies, including the 24-hour notice commitment. [CONFIRM]

Testing and review

  • This plan has not yet been tested. [CONFIRM date of first test]
  • Innorve will review it at least yearly and after any major incident or provider change. [CONFIRM]