Reliability and recovery

GeckoGuard publishes live component state, measured latency, incidents, and up to 90 days of recorded availability on the status page. Missing monitoring data is shown as unavailable; it is never counted as healthy.

Webhook delivery contract

Webhook requests have a 10-second timeout and are HMAC-SHA256 signed. A non-2xx response or network failure is retried up to six total attempts with exponential delays beginning at 30 seconds. Each attempt and receiver response is visible in the dashboard, and an operator can replay a failed delivery with an idempotency key. Permanent URL-safety failures are not retried.

See Webhooks for signature verification, timestamp tolerance, delivery history, and replay instructions.

Backup and recovery targets

The production operating target is:

MeasureTarget
Database recovery point (RPO)5 minutes or less through WAL/PITR
Service restoration time (RTO)30 minutes or less
Hot backup retention30 days
Cold backup retention1 year
Restore verificationMonthly snapshot check and quarterly recovery drill

PostgreSQL records—including accounts, organizations, products, licenses, authorization state, audit logs, and webhook history—are in backup scope. Uploaded product files require object-storage replication. Redis contains short-lived nonce, rate-limit, and cache data and is rebuilt rather than restored.

These are engineering recovery objectives, not a contractual SLA. A recovery incident and any known data-loss window will be reported on the status page. Enterprise buyers who require contractual availability or recovery terms should contact support before purchase.