> For the complete documentation index, see [llms.txt](https://vnx.gitbook.io/vnx-global/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vnx.gitbook.io/vnx-global/institutional/risk/business-continuity.md).

# Business Continuity

*24-hour recovery objective, 99.5% uptime target, multi-region failover, and annual disaster-recovery testing.*

## Scope

The Business Continuity and Disaster Recovery Policy applies to VNX Global Ltd.’s employees, staff, officers and directors, and establishes the framework for business continuity, incident management and disaster recovery. The policy supports the continuity of VNX’s operations, platform, technology infrastructure, personnel arrangements and critical business functions.

The Stablecoin Risk Management Policy separately requires documented disaster recovery and business continuity arrangements, tested at least annually, including contingency funding arrangements for liquidity and financial-resource replenishment.

## Principles

* **24-hour recovery objective** — VNX aims to resume necessary operations within approximately 24 hours after a material risk event.
* **99.5% availability** — the VNX platform availability target is 99.5%, aligned with AWS SLA.
* **No single point of failure** — services are designed with redundancy across hosts and data centres so that a single host or data-centre failure should not affect overall service availability.
* **Annual DR testing** — the CTO must perform Disaster Recovery tests at least annually.
* **Alternative-cloud capability** — for a prolonged global AWS outage, VNX has technical capability to bring up critical services on an alternative cloud provider, such as Google, with no or minimal loss of customer information and transactional data.

## Key controls

| Control                      | Threshold / cadence                                                                                                             | Owner                |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| Recovery Time Objective      | Approximately 24 hours for necessary operations                                                                                 | Executive Management |
| Platform availability        | 99.5% target                                                                                                                    | CTO / IT Operations  |
| DR test cadence              | At least annual                                                                                                                 | CTO                  |
| Redundancy                   | Single host/data-centre failure should not affect overall availability                                                          | CTO / IT Operations  |
| Alternative-cloud capability | Critical services capable of migration in prolonged AWS outage                                                                  | CTO / IT Operations  |
| Log preservation             | Logs preserved after system sessions and accessible via AWS CloudWatch                                                          | IT Operations        |
| Vital data backup            | Backups rotated to a physically separate location and retained as required by business, law or regulation                       | IT Operations        |
| Remote-work readiness        | Key employees equipped with VPN-enabled laptops                                                                                 | IT                   |
| DR location                  | Pre-arranged DR locations available on activation                                                                               | Executive Management |
| Incident response            | Impact assessment, CEO involvement, assignment, evidence preservation, root-cause analysis, mitigation and policy-update review | Executive Management |
| Contingency funding          | Documented under stablecoin recovery and resolution planning                                                                    | Board                |

## Reporting and review

The BCP is reviewed annually to reflect regulatory changes, new systems, new tools, new processes and business-continuity learnings. Incidents may be reported externally through customer-support channels or internally by any team member, and known or suspected incidents must be escalated to Executive Management and, where necessary, the CEO.

## Related policies and pages

* [Enterprise Risk Framework](/vnx-global/institutional/risk/enterprise-risk-framework.md)
* [Stablecoin Specific Risks](/vnx-global/institutional/risk/stablecoin-specific-risks.md)
