Back to Compliance

RepLogix Business Continuity & Disaster Recovery Plan

Effective Date: August 8, 2026

This Business Continuity and Disaster Recovery (BCDR) Plan defines the procedures RepLogix follows to maintain operations and recover from disruptions. It identifies critical systems, recovery objectives, and the steps to restore service following an incident.

1. Purpose and Scope

This plan applies to RepLogix's core services, including the web application, mobile app, database, and supporting infrastructure. It covers disruptions caused by system failures, natural disasters, cyber incidents, and third-party outages.

2. Recovery Objectives

SystemRTO (Recovery Time Objective)RPO (Recovery Point Objective)
RepLogix Application (web + mobile)4 hours1 hour
Production Database2 hours15 minutes
Authentication System2 hours1 hour
Notification Services (Email/SMS)8 hoursN/A (stateless)
Reporting & Export Functions8 hours1 hour

RTO = maximum acceptable downtime. RPO = maximum acceptable data loss. Actual recovery times depend on Base44 infrastructure capabilities.

3. Critical Systems and Dependencies

  • Base44 Platform: Application hosting, database, authentication, and file storage
  • Stripe: Payment processing and subscription management
  • Resend: Email delivery for notifications and invitations
  • Twilio: SMS notifications
  • Google OAuth: Authentication provider

RepLogix is hosted on the Base44 platform, which maintains SOC 2 Type II and ISO 27001 certifications. Infrastructure redundancy, replication, and physical security are managed by Base44 and its cloud providers. See the Base44 Security Trust Center for details.

4. Backup Strategy

  • Database backups are maintained by Base44 infrastructure with encrypted at-rest storage
  • Backups are stored within the United States
  • Backup frequency and retention are governed by Base44's SOC 2 / ISO 27001 controls
  • RepLogix also maintains a data export function allowing customers to export their data as CSV

5. Restoration Testing

  • Backup restoration procedures are tested at least annually
  • Restoration tests verify data integrity and completeness
  • Test results are documented, including restoration time and any issues encountered
  • Remediation actions are tracked if restoration issues are identified

6. Disaster Recovery Procedures

System Failure:

  • Monitor alerts and confirm the failure with Base44 infrastructure status
  • Initiate failover or recovery through the Base44 platform
  • Verify data integrity after restoration
  • Communicate status to affected customers

Data Corruption:

  • Identify the scope of corruption
  • Restore affected data from the most recent valid backup
  • Validate restored data with affected customers where possible
  • Document the incident and root cause

Third-Party Outage:

  • Confirm the outage with the third-party provider's status page
  • Activate fallback procedures or communicate degraded service to customers
  • Monitor for restoration and verify functionality when service returns

7. Business Continuity

In the event of a prolonged outage, RepLogix maintains continuity through:

  • Customer data can be exported as CSV, allowing manual continuity if the application is unavailable
  • Communication channels (email, phone) remain available through third-party providers independent of the application
  • Critical personnel have documented contact information available outside of the application
  • Incident response procedures are activated to coordinate recovery (see Incident Response Plan)

8. Plan Testing and Review

  • This BCDR Plan is reviewed and updated at least annually
  • Disaster recovery procedures are tested at least annually
  • Lessons learned from tests and actual incidents are incorporated into plan updates

9. Contact

For questions about this plan, contact:

RepLogix Security

Email: RepLogixapp@gmail.com