Every device holds a complete encrypted vault that works offline. Every pinned region can run a live in-jurisdiction replica — even on a second cloud provider. And where physics or law set a hard limit, we tell you exactly where it is.
First principles
Most continuity conversations blur the two. We split them — because one is effectively solved, and the other deserves real engineering.
Eleven-nines-class object storage, a control plane with 30-day point-in-time recovery, and — most importantly — a complete encrypted copy of every vault on every user's device. Even a total loss of all server-side data leaves every user with a working vault to rebuild from. This holds on every plan, with nothing to configure.
A region blip, a provider incident, a severed cable — temporary outages are the risk that actually matters, and they're where the machinery on this page lives: offline-first clients, dual-written replicas, automatic failover, and continuous probing.
The practical result: a Veridenti outage is a sync delay, never a lockout — and never a data loss.
Always on — every plan, every tier
Three protections are simply inherited. For most organizations there is nothing to configure — redundancy is the default, not an add-on.
A backend outage is never a lockout. Reads come from the local encrypted vault; writes buffer on-device and reconcile automatically when the backend returns. Most cloud vaults are unusable the moment their servers are — ours isn't.
The application tier runs across a global edge with no single region to fail, and default vault storage is multi-region redundant. Redundancy is inherited, not assembled.
The control plane supports 30-day continuous restore — recovery from accidental deletion, a bad migration, or corruption without a backup-restore project. There is no nightly backup job to fail.
In-jurisdiction disaster recovery Enterprise · pinned regions
Data residency in 20+ countries — including bring-your-own buckets — pins your ciphertext to one jurisdiction. Pinning creates a continuity question: you cannot fail over across a border without breaking residency. Our answer is a live DR replica inside the jurisdiction, dual-written on every change.
Recovery objectives
Every target below maps to a shipped mechanism — and the failover-and-reconcile path is exercised by an automated test suite on every deploy, not once a year in a binder.
| Objective | Commitment | The mechanism behind it |
|---|---|---|
| RPO — data loss | Near-zero | Committed writes are dual-written in pinned regions, and the client's local vault is an independent copy — three copies of every credential, one of them in your users' hands. |
| RTO — reads | Immediate | Offline-first serves reads from the local vault with zero dependency on any backend; pinned regions add automatic read-failover to the DR replica. |
| RTO — writes | Under 15 minutes | Through a full region outage: writes buffer on-device and, where a replica is configured, continue against the DR replica — reconciling when the primary returns. |
The last line of defense
Resilience isn't only about outages. If a datacenter is seized, subpoenaed, or compelled — anywhere, under any law — the only thing there to take is ciphertext no one can decrypt. The keys never left your devices. The worst legal or physical event in a jurisdiction is still not a data event.
Detection & response
Failover you don't monitor is failover you don't have. Ours is probed continuously and heals itself — before a human is even paged.
A self-healing monitor live-probes every bound region around the clock. An unreachable region automatically opens a status incident and a support ticket — no one has to notice first.
When a failed primary comes back, its DR-held writes reconcile automatically. Failover and recovery are code paths, not runbook steps.
status.veridenti.com shows our live health — and surfaces upstream Cloudflare and AWS status alongside it, so you see the whole dependency picture we see.
In fairness
Any vendor claiming unlimited availability inside a single-country pin is claiming something physics and law don't allow. Here is ours, stated plainly.
If you pin data to one country, a true country-wide event — a major cable cut, national force majeure — pauses that region's sync until in-country capacity returns. We will not quietly move your data across a border to avoid it. Residency caps achievable availability for that zone; that is your informed trade-off, not a defect.
Two backstops still hold even then: offline-first means every user keeps full local vault access — only sync pauses — and zero-knowledge means that even a seizure of both copies yields ciphertext. Within a broader zone like the EU or US, cross-provider and multi-country replicas avoid the ceiling entirely — without data ever leaving the jurisdiction.
If a continuity page has no limits on it, it isn't a continuity page. It's marketing.
Next step
The full BC/DR plan — failure-mode matrix, recovery mechanics, exercise cadence, roles — is available for your security review. Ask the region-outage question. Ask the seizure question. We built for both.
Resilience, verified — not asserted.
Read the planthe full BC/DR plan — self-serve, no gate
Live statusstatus.veridenti.com — ours + upstream providers
Talk to salesresidency + DR design for your jurisdictions