Offer · Operate Early access

Every backup product says its jobs succeeded.
None can say your service comes back.

A business service is made of parts that several products protect, and some parts none of them do. Recovery Proof proves recoverability per business service: coverage reconciled against your CMDB, restore drills in isolation across every product the service depends on, recovery time and data loss measured, and evidence your auditors can re-check.

Four steps, per business service

1

Reconcile

What your CMDB says the service is made of, against everything your backup, replication and snapshot products protect.

2

Drill

A restore into an isolated environment you declare, across every product the service depends on, from the recovery point you choose.

3

Measure

Recovery time to the moment the service answers — not to the end of a job — and data loss, both from the products' own records.

4

Prove

Every plan, result and reconciliation signed and kept where the agent that ran the drill cannot rewrite it. The copy is torn down.

It says what it could not see

A listing that was cut short proves nothing either way. So every part of a service lands in one of four states, and coverage is always given as a range until nothing is unknown.

Protected

Covered

At least one product protects it, with a last good copy inside the recovery point objective.

Stale

Covered, too old

Protected, but every known copy is older than the service can afford to lose.

Unprotected

Nothing covers it

Said only when every product's listing was read completely.

Unknown

Could not be seen

A listing was incomplete or a match was ambiguous. We name the missing source instead of guessing.

What the agents may never do at the start

Never

  • Restore in place during a drill, or anywhere outside the isolated environment you declared
  • Restore into production without a change a person approved in your ticketing tool
  • Record the result of a drill they ran themselves
  • Call a part unprotected on an incomplete read
  • Delete a copy, change a backup policy, or approve anything

Always

  • Check the plan, the approval, the isolation test and the destination just before a drill starts
  • Stop and call a person when the state after an action is uncertain or isolation is in doubt
  • Open a ticket for every critical gap and every drill that did not prove recovery
  • Tear the isolated copy down, and confirm it

How the drills earn their autonomy

1 · Approve each

Your recovery owner approves every drill before it starts. Reconciliation, tickets and evidence run on their own from day one.

2 · Pre-authorised

A class of drill — these services, these products, this destination, these hours — runs without per-drill approval once its record holds: drills run as planned without correction, no isolation breach, no copy left behind.

3 · Production, by change

Restoring into production, or promoting a clean-room rebuild, goes through your change process and a person's approval, and is earned class by class there.

Any breach sends a class straight back to per-drill approval. Declaring a disaster or a cyber recovery stays a human decision; the team brings the evidence.

What is live, what early access adds

Live on the platform today

  • Connectors to backup, replication and storage-snapshot products, to your CMDB and to your ticketing tool
  • Approval gates with a person's decision recorded
  • Tamper-evident audit trail of every action
  • Autonomy earned on measured compliance
  • Installation on your premises

Built with early-access customers

  • Coverage reconciliation per business service, with unknowns stated
  • Signed drill plans and results, with recovery time and data loss measured
  • Drill start and teardown on more products, and multi-product sequencing per service
  • Pre-authorised drill classes and their promotion record
  • Evidence packs mapped to the frameworks you answer to, such as DORA and NIS2

Priced per protected critical service, and per drill that proves its recovery time — not per terabyte. Your own infrastructure team runs Recovery Proof; if a partner operates it for you, they run the same thing.

See every offer · Change Guard · Agentic infrastructure operations