Version 1.0 · Draft · Owner: Engineering Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Engineering Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Ensure Touch2Sign can maintain or rapidly restore eSignature and eWitness services following disruption to AWS infrastructure, application failure, or regional outage. Supports ISO 27001 A.5.29 and SOC 2 Availability criteria.
Covers:
Excludes: customer-owned integrations outside Touch2Sign control (e.g. customer SMTP relays).
| Metric | Target | Notes | RTO (Recovery Time Objective) | 4 hours | Restore core signing and document access |
|---|---|---|
| RPO (Recovery Point Objective) | 1 hour | Maximum acceptable data loss |
| Communication SLA | 1 hour | Customer status update after confirmed major outage |
Tier 2 functions (reporting, non-critical admin) may recover within 24 hours.
| System | Function | Priority | App Runner / application tier | Signing, witnessing, API | P1 |
|---|---|---|
| Amazon RDS (PostgreSQL) | Documents metadata, audit_log, accounts | P1 |
| Amazon S3 | Document PDFs, signed artifacts | P1 |
| Amazon Cognito | Authentication | P1 |
| CloudFront | CDN, TLS termination | P1 |
| AWS SES | Transactional email (signing links, OTP) | P2 |
| Stripe | Billing (degraded mode acceptable short-term) | P3 |
| Item | Current state | Primary region | eu-west-1 (Ireland) |
|---|---|
| Data residency | Customer data stored in eu-west-1 unless sub-processor DPA specifies otherwise |
| Multi-region active-active | Not currently deployed — single-region with backup restore |
| Failover region | eu-west-2 (London) or eu-central-1 (Frankfurt) — target for future DR drill |
Cross-region failover requires CEO and Engineering Lead approval and customer communication if data location changes.
| Control | Configuration | Automated backups | Enabled; retention 35 days minimum |
|---|---|
| Backup window | Off-peak UTC window |
| Point-in-time recovery | Enabled |
| Manual snapshots | Before major migrations or schema changes |
| Encryption | KMS-encrypted backups |
| Control | Configuration | Versioning | Enabled on document buckets where supported |
|---|---|
| Cross-region replication | Evaluate for critical buckets — target Q4 |
| Lifecycle | Per Data Retention & Disposal Policy |
docs/compliance/ and engineering wiki docs/QA_SIGN_FLOW.md smoke tests) | Test | Frequency | Owner | Evidence | RDS point-in-time restore to isolated instance | Semi-annual | Engineering Lead | Test report + ticket |
|---|---|---|---|
| S3 object restore (versioning) | Annual | Engineering | Checklist |
| Full DR tabletop | Annual | Security + Engineering | Meeting notes |
| Signing smoke test post-restore | Every restore test | QA / Engineering | QA_SIGN_FLOW.md results |
First restore test target: Month 6 of compliance programme.
| Role | Responsibilities | Incident Commander | Declares DR; coordinates recovery; customer comms |
|---|---|
| Engineering Lead | Executes restore; validates data integrity |
| DPO | Assesses personal data impact; breach notification if applicable |
| CEO / Comms | External statements; enterprise customer calls |
Reviewed annually and after every DR test or major AWS architecture change.
Approval
| Name | Role | Signature | Date | Robert | CEO / Engineering Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com