Skip to content

Documentation

Backup and Recovery

Backup and restore requirements for hosted environments, including how current evidence is reviewed.

RuntraceLast updated July 24, 2026

Service architecture

Hosted Runtrace stores customer operational data in PostgreSQL, separately from the application process. This keeps fleet history, findings, audit events, reports, and workflow state available across application releases and restarts.

Backups

  • Hosted production environments must use scheduled PostgreSQL backups that run outside the application process.
  • Access to backup systems must be restricted to authorized operators.
  • Backup copies must follow a defined retention cycle and be removed as they expire.
  • Published security documentation excludes database credentials, private network details, raw customer records, and operator commands.

Restore testing

Runtrace requires restoration to be tested in an isolated environment before a hosted environment is approved for customer data. Validation covers application health, tenant-scoped data, device and finding history, audit records, reports, and customer exports. Current evidence can be reviewed during a security assessment without exposing credentials or customer data.

Recovery objectives

Runtrace maintains internal recovery targets for the hosted service. Contractual recovery point and recovery time objectives apply only when stated in an Enterprise order form or service-level agreement.

Customer data after deletion

Deleting an organization removes its active records from the application. Residual backup copies expire through the normal backup-retention cycle and are used only for disaster recovery. If a backup is restored, deletion records are reapplied before the service returns to normal operation.

Customer responsibilities

Customers should maintain their own copies of reports and exports needed for long-term compliance or internal records. Runtrace backups support service recovery and are not a customer-controlled archive.