Resilience and continuity
Availability, backup, recovery and what happens to a regulated institution’s records if the relationship ends.
Last updated 23 July 2026 · Trust Center
1. Availability
Availability commitments, if any, are on your order form rather than asserted on a web page — a number published for everyone is a number negotiated with nobody. Non-production environments carry no availability commitment. Current operational state is on status.
2. Backup and recovery
Data is backed up on a schedule, and recovery objectives for your deployment are recorded on the order form. Two points a reviewer should press on, so we state them first:
- A backup you have never restored is a hypothesis. Restore testing is part of the operating routine, not an annual event.
- Backups interact with deletion. Deletion under clause 11 of the DPA covers backups on their ordinary expiry cycle rather than immediately. We will tell you what that cycle is for your deployment.
3. Incident response
We notify you without undue delay and within seventy-two hours of becoming aware of a personal-data breach affecting data we process for you, with the nature, scope so far as known, likely consequences, measures taken and a contact point — and we send the first notification before everything is known rather than waiting until it is.
Because authorization is per data element and per purpose, containment can usually be scoped to a purpose, delegation or record class rather than by disabling an institution. That is the difference between an incident and an outage.
4. Exit and portability
A regulated institution cannot simply stop having records, so the exit plan is agreed before access ends rather than after. On termination, at your choice, we return or delete your data under clause 11 of the DPA, and we agree a transition period and an export format in advance.
If you are evaluating us, ask for the export format during diligence. A vendor who cannot describe how you leave has not thought about the part of the relationship you care about most if it goes wrong.
5. Concentration risk
Two dependencies apply to every deployment and should appear in your own concentration analysis: Microsoft Azure for hosting and Twilio for SMS and telephony. Both are in the register. Deployment-specific dependencies are in your completed Exhibit C.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.