Veridenti
Resilience & Business Continuity

When a cloud vault's backend goes down, the vault goes with it. Veridenti keeps working — by architecture, not by promise.

Every device holds a complete encrypted vault that works offline. Every pinned region can run a live in-jurisdiction replica — even on a second cloud provider. And where physics or law set a hard limit, we tell you exactly where it is.

~0RPO — committed data is never lost
ImmediateRTO, reads — offline-first plus automatic failover
<15minRTO, writes — through a full region outage
10minhealth-probe cadence, every region, around the clock

First principles

Durability and availability are different problems. We solve them separately.

Most continuity conversations blur the two. We split them — because one is effectively solved, and the other deserves real engineering.

Durability — effectively solved

Could your data be permanently lost? No.

Eleven-nines-class object storage, a control plane with 30-day point-in-time recovery, and — most importantly — a complete encrypted copy of every vault on every user's device. Even a total loss of all server-side data leaves every user with a working vault to rebuild from. This holds on every plan, with nothing to configure.

Availability — the real design target

Could an outage take you offline? That's what we engineer against.

A region blip, a provider incident, a severed cable — temporary outages are the risk that actually matters, and they're where the machinery on this page lives: offline-first clients, dual-written replicas, automatic failover, and continuous probing.

The practical result: a Veridenti outage is a sync delay, never a lockout — and never a data loss.

Always on — every plan, every tier

What every deployment gets

Three protections are simply inherited. For most organizations there is nothing to configure — redundancy is the default, not an add-on.

Offline-first client

A backend outage is never a lockout. Reads come from the local encrypted vault; writes buffer on-device and reconcile automatically when the backend returns. Most cloud vaults are unusable the moment their servers are — ours isn't.

Platform redundancy

The application tier runs across a global edge with no single region to fail, and default vault storage is multi-region redundant. Redundancy is inherited, not assembled.

Point-in-time recovery

The control plane supports 30-day continuous restore — recovery from accidental deletion, a bad migration, or corruption without a backup-restore project. There is no nightly backup job to fail.

Your Device
OFFLINE-READY
local encrypted vault · offline-capable
Veridenti Sync
stores ciphertext only · region-pinned
sync ciphertext · TLS
buffer → reconcile on reconnect
backend can go down
The device holds a complete local vault, so reads and writes keep working even if the backend is unavailable. Changes buffer and reconcile automatically when the connection returns.

In-jurisdiction disaster recovery  Enterprise · pinned regions

DR that never crosses a border

Data residency in 20+ countries — including bring-your-own buckets — pins your ciphertext to one jurisdiction. Pinning creates a continuity question: you cannot fail over across a border without breaking residency. Our answer is a live DR replica inside the jurisdiction, dual-written on every change.

Regional Redundancy
DR-READY
Region A
sealed replica
Region B
sealed replica
Every write lands in both stores. If the primary is unreachable, reads fail over automatically and the replica becomes authoritative for writes — reconciling back when the primary recovers. Failing over to another jurisdiction is refused at construction: the residency guarantee cannot be silently violated, even during a disaster.
Continuity is visible, not assumed: the console's Data Residency → Continuity & Disaster Recovery panel shows each region's live status — healthy, failed over to DR, or unreachable — whether a replica is configured and healthy, and your RTO/RPO targets.

Recovery objectives

Architectural, not aspirational

Every target below maps to a shipped mechanism — and the failover-and-reconcile path is exercised by an automated test suite on every deploy, not once a year in a binder.

ObjectiveCommitmentThe mechanism behind it
RPO — data loss Near-zero Committed writes are dual-written in pinned regions, and the client's local vault is an independent copy — three copies of every credential, one of them in your users' hands.
RTO — reads Immediate Offline-first serves reads from the local vault with zero dependency on any backend; pinned regions add automatic read-failover to the DR replica.
RTO — writes Under 15 minutes Through a full region outage: writes buffer on-device and, where a replica is configured, continue against the DR replica — reconciling when the primary returns.

The last line of defense

Zero-knowledge is a continuity property

Resilience isn't only about outages. If a datacenter is seized, subpoenaed, or compelled — anywhere, under any law — the only thing there to take is ciphertext no one can decrypt. The keys never left your devices. The worst legal or physical event in a jurisdiction is still not a data event.

Detection & response

Watched by machines, not hoped about

Failover you don't monitor is failover you don't have. Ours is probed continuously and heals itself — before a human is even paged.

Probed every 10 minutes

A self-healing monitor live-probes every bound region around the clock. An unreachable region automatically opens a status incident and a support ticket — no one has to notice first.

Recovery is automatic

When a failed primary comes back, its DR-held writes reconcile automatically. Failover and recovery are code paths, not runbook steps.

Public, upstream-aware status

status.veridenti.com shows our live health — and surfaces upstream Cloudflare and AWS status alongside it, so you see the whole dependency picture we see.

In fairness

The one limit we won't engineer around

Any vendor claiming unlimited availability inside a single-country pin is claiming something physics and law don't allow. Here is ours, stated plainly.

Sovereignty vs. availability

A single country can't be recovered from outside that country.

If you pin data to one country, a true country-wide event — a major cable cut, national force majeure — pauses that region's sync until in-country capacity returns. We will not quietly move your data across a border to avoid it. Residency caps achievable availability for that zone; that is your informed trade-off, not a defect.

Two backstops still hold even then: offline-first means every user keeps full local vault access — only sync pauses — and zero-knowledge means that even a seizure of both copies yields ciphertext. Within a broader zone like the EU or US, cross-provider and multi-country replicas avoid the ceiling entirely — without data ever leaving the jurisdiction.

If a continuity page has no limits on it, it isn't a continuity page. It's marketing.

Next step

Bring us your worst scenario.

The full BC/DR plan — failure-mode matrix, recovery mechanics, exercise cadence, roles — is available for your security review. Ask the region-outage question. Ask the seizure question. We built for both.

Resilience, verified — not asserted.


Read the planthe full BC/DR plan — self-serve, no gate

Live statusstatus.veridenti.com — ours + upstream providers

Talk to salesresidency + DR design for your jurisdictions