Phase 1D · reliability before activation

A backup is useful only after a proven restore.

KIIRAAY separates availability, backup, restore, recovery, and incident response. The public plan shows controls without revealing server paths, accounts, secrets, on-call contacts, or exploitable operational detail.

Activeminimized public health
Unprovenclean restore
Unnamedon-call and command
Blockedsensitive activation

Provisional objectives

A planning target is not a promise.

For the public site and synthetic scenarios only, the blueprint provisionally proposes a maximum 24-hour loss and four-hour service return. These values are neither approved nor measured. The future transactional platform needs separate objectives.

Planning RPO24 h

Public and synthetic only · unapproved · unmeasured.

Planning RTO4 h

Public-service return target · unapproved · unmeasured.

Future transactionsTo define

No real objective activates before budget, architecture, ownership, and exercise.

Incident lifecycle

From detection to verified return.

Every step will require an owner, reliable time, a traceable decision, and proportionate communication.

  1. 01
    Detect

    Measure a verifiable signal without logging personal content or secrets.

  2. 02
    Declare

    Classify the incident, name approved command, and create an evidence reference.

  3. 03
    Preserve

    Retain useful evidence with integrity, limited access, and chain of custody.

  4. 04
    Contain

    Close a feature, revoke access, or isolate a component without expanding exposure.

  5. 05
    Restore

    Return from controlled artifacts and backups in a clean environment.

  6. 06
    Verify

    Compare counts, hashes, rules, and flags before progressive reopening.

  7. 07
    Learn

    Document cause, decisions, impact, correction, and follow-up without blame.

Classification

Four levels, no invented commander.

SEV-1

Critical

Data exposure, compromise, election-integrity event, or critical nationwide unavailability.

Draft · owner unnamed
SEV-2

Major

Critical function failure, limited abuse, or contained integrity loss.

Draft · owner unnamed
SEV-3

Degradation

Slow or partially unavailable service with a safe alternative.

Draft · owner unnamed
SEV-4

Anomaly

Minor defect without immediate sensitive impact, to track and correct.

Draft · owner unnamed

Restore evidence

The test starts from a clean environment.

A future restore must rebuild the application, database, controls, and keys through a separated procedure. It must never automatically reopen enrollment, messages, maps, identity, voice, or sessions.

01Inventory

Artifacts, configuration, migrations, database, objects, keys, and dependencies.

02Verify

Hashes, encryption, dates, coverage, expiry, and job success.

03Restore

Isolated environment, rotated secrets, and minimal access before data.

04Reconcile

Counts, versions, withdrawals, revocations, audit, and closed flags.

05Measure

Actual loss, duration, errors, decisions, and objective gaps.

06Clean up

Remove the test environment and retain only approved evidence.

Twelve controls

Eleven proofs remain.

The public probe exists. Every other item stays blocking until tested, assigned, and approved.

Safe public status

Operational detail stays private.

The public can verify general status, limits, and gates. Contacts, paths, accounts, backups, keys, incident evidence, and executable instructions remain in a protected register.