Business Continuity & Disaster Recovery Plan

Updated: February 15, 2026

Keelio Software, LLC ("Company," "we," "us," or "our") maintains a Business Continuity and Disaster Recovery (BCDR) Plan to help ensure that our services remain available, and that customer data remains protected, in the event of a significant disruption. This page describes, at a public level, the objectives and practices behind our BCDR program. It does not disclose internal technical configurations, credentials, or other information that could undermine our security posture.

1. PURPOSE & SCOPE

This plan applies to events that could disrupt Keelio Software's ability to deliver its services, including hardware and infrastructure failures, data center outages, natural disasters, extended power or network loss, and other significant incidents affecting availability. It works alongside our Incident Response Plan, which governs our response to security and data incidents.

2. BUSINESS IMPACT ANALYSIS

We periodically assess our systems and services to identify which components are most critical to our customers, such as our web application, databases, and background processing services. This analysis helps us prioritize recovery efforts so that the most critical functions are restored first following a disruption.

3. RECOVERY OBJECTIVES

Our BCDR planning is guided by two key targets:

  • Recovery Time Objective (RTO). The maximum acceptable amount of time our services may be unavailable following a disaster before they are restored.
  • Recovery Point Objective (RPO). The maximum acceptable amount of data loss, measured in time, that could occur as a result of a disaster.

These objectives are reviewed periodically and inform our backup frequency and infrastructure redundancy decisions described below.

4. BACKUP STRATEGY

All customer data is backed up daily. Backups are retained for a defined period to support point-in-time recovery and are stored separately from production systems so that a single failure is unlikely to affect both production data and its backups. Backup restoration procedures are exercised periodically as part of our testing program described in Section 9.

5. INFRASTRUCTURE REDUNDANCY & FAILOVER

Our infrastructure is hosted with a cloud provider that offers redundant power, networking, and hardware within its data centers. Where practical, we design our systems to reduce single points of failure, and we rely on our hosting provider's own resiliency and business continuity practices as part of our overall recovery strategy. See our Trust Center for more information about our hosting provider's compliance and certifications.

6. DISASTER DECLARATION & ACTIVATION

When a significant disruption is identified, our response team assesses the scope and severity of the event to determine whether it meets the threshold for a formal disaster declaration. Upon declaration, the team follows documented recovery procedures to restore affected systems and services in order of business priority, as identified in our Business Impact Analysis.

7. ROLES & RESPONSIBILITIES

Keelio Software designates internal personnel responsible for coordinating our response to a disruption, including assessing impact, directing recovery efforts, and coordinating communications. Depending on the nature of the event, our team may also engage our hosting provider and other third-party vendors whose services are part of our recovery process.

8. CUSTOMER COMMUNICATION

In the event of a significant service disruption, we will make reasonable efforts to keep affected customers informed, including providing status updates as recovery efforts progress and, upon resolution, a summary of the event and the actions taken. Communications will be sent using the contact information on file for your account.

9. TESTING & PLAN MAINTENANCE

We periodically test elements of our BCDR Plan, including backup restoration procedures, to validate that they continue to meet our recovery objectives. The plan is reviewed and updated on a regular basis, and following any significant incident, to reflect changes in our systems, services, and business needs.