Reliability and recovery
GeckoGuard publishes live component state, measured latency, incidents, and up to 90 days of recorded availability on the status page. Missing monitoring data is shown as unavailable; it is never counted as healthy.
Webhook delivery contract
Webhook requests have a 10-second timeout and are HMAC-SHA256 signed. A non-2xx response or network failure is retried up to six total attempts with exponential delays beginning at 30 seconds. Each attempt and receiver response is visible in the dashboard, and an operator can replay a failed delivery with an idempotency key. Permanent URL-safety failures are not retried.
See Webhooks for signature verification, timestamp tolerance, delivery history, and replay instructions.
Backup and recovery targets
The production operating target is:
| Measure | Target |
|---|---|
| Database recovery point (RPO) | 5 minutes or less through WAL/PITR |
| Service restoration time (RTO) | 30 minutes or less |
| Hot backup retention | 30 days |
| Cold backup retention | 1 year |
| Restore verification | Monthly snapshot check and quarterly recovery drill |
PostgreSQL records—including accounts, organizations, products, licenses, authorization state, audit logs, and webhook history—are in backup scope. Uploaded product files require object-storage replication. Redis contains short-lived nonce, rate-limit, and cache data and is rebuilt rather than restored.
These are engineering recovery objectives, not a contractual SLA. A recovery incident and any known data-loss window will be reported on the status page. Enterprise buyers who require contractual availability or recovery terms should contact support before purchase.