The situation.
Shortly after we started working with a client, an internal system their business depended on lost its production database. The system had been built quickly on a hosted low-code platform, worked well enough day to day, and had no backup story of its own. The wipe was not ours, but the business was ours to keep running.
The constraint.
The data lived inside a hosted platform, so the usual recovery moves were not available to us. Any snapshots that existed belonged to the platform's developers, not to the client, and the business needed to be operating in the morning.
What we found.
The platform kept developer-side snapshots that customers could not see or restore themselves. Getting to them meant working directly with the platform's developers, that night, and knowing exactly what to ask for.
What we built.
We worked with the platform's team through the night to locate the right snapshot and restore it, verifying the recovered data against what the business knew to be true before anyone logged in the next morning. Then we made the platform's snapshots irrelevant: two staggered scheduled jobs now take an offsite snapshot of the production database every three hours, to two separate servers, encrypted at rest, so the client owns its own recovery from now on and no single failure can take both copies.
What changed.
The business opened the next morning with its data. The next database problem will be a restore from a copy the client owns, measured in minutes, not a night on the phone.
- overnight recovery from platform-side snapshots
- 2 staggered offsite snapshot jobs every 3 hours
- 2 destinations, encrypted at rest
Related work
If this sounds like your operation, apply to work with us.
Apply