AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Backup and disaster recovery

Backup design

The 3-2-1-1-0 pattern and local-first replicas.

How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration

C0221How are backups organized?

By the 3-2-1-1-0 pattern: three copies, two media, one off-site, one immutable or offline, and zero verification errors. Tiers run from a synchronous replica to offline media held in-country.

Designed, not yet builtPermalink

C0222Is the local database a backup?

The local database is the operational primary and the cloud copy is an encrypted backup replica. This inversion is what allows outage survival.

Designed, not yet builtPermalink

C0223Can backups be encrypted so the cloud cannot read them?

Yes: bundles are encrypted client-side and signed, so the sync hub stores ciphertext and cannot read them.

Designed, not yet builtPermalink

C0224Can ransomware delete my backups?

The design gives backup agents write-only credentials, keeps an immutable copy in a separate account and an offline copy with no reachable credentials. Nothing is built yet.

Designed, not yet builtPermalink

C0225How fast can I recover?

Recovery objectives in the specification are planning targets such as minutes for a single node and hours for a full server from the cloud replica. They are unmeasured and not promised.

Designed, not yet builtPermalink

C0226What recovery point does a clinic get?

Proposed values only. The specification marks all recovery objectives as recommended and to be validated, and no figure is contractual.

Open decisionPermalink

C0227Are restores tested?

Quarterly restore drills to a clean-room environment are planned, with a pass rate reported. No drill has been run because backup and restore are not built.

Designed, not yet builtPermalink

C0228How is a restore verified?

By signatures, hash chain and ledger anchors, in an isolated environment with malware scanning, then promoted with two-person approval.

Designed, not yet builtPermalink

C0229Can tampering with backups be detected?

Each bundle range is hashed and anchored on the ledger, so deleted or altered ranges show up on restore.

Designed, not yet builtPermalink

C0230What if the ledger and database disagree after a restore?

Consent and authority follow the ledger; clinical content follows the database with a logged review.

Designed, not yet builtPermalink

C0231What happens to deleted patients in old backups?

Their keys are destroyed, so immutable ciphertext stays unreadable, and tombstone bundles propagate the erasure.

Designed, not yet builtPermalink

C0232Where are offline backups kept?

In-country, in clinic or partner custody, with split-custody key escrow. Custody arrangements are not yet defined.

Designed, not yet builtPermalink

C0233How do backups handle erasure versus immutability?

Crypto-shredding resolves the conflict, subject to legal opinion on whether it counts as erasure.

Designed, not yet builtPermalink

C0234Does the local backup database sync to another clinic?

Clinic-to-clinic sync is designed where the profile and consent allow, for medium and large tiers.

Designed, not yet builtPermalink

C0235How is a replica kept consistent?

Gapless sequence numbers, hash chains and replay protection, with retransmission on any gap.

Designed, not yet builtPermalink

C0236How big is the backup?

Sizing is an open item: structured data is estimated at 5 to 50 MB per patient per year, imaging by modality, all to be measured.

Designed, not yet builtPermalink

C0237Is there a backup in the pilot?

No. Backup, restore drills and disaster recovery have not started; the pilot is a demonstration hub with re-seedable synthetic data.

Open decisionPermalink

C0238What about regional disasters?

An in-country disaster recovery site with a 24 hour recovery point target is the design proposal. It is a proposal only.

Designed, not yet builtPermalink

C0239Is there protection against insider deletion?

Immutable retention, no delete rights for the sync agent and dual-approval purge make single-person deletion impractical by design.

Designed, not yet builtPermalink
See the synthetic-data demo first.Request a demo