Early access for UK transport operators View the Founding Customer Programme

Business continuity policy

GLS is designed so that the platform can form a realistic and dependable part of an operator’s continuity plan — supporting resilience rather than becoming a single point of failure.

Version: 0.6 Last reviewed: Jan 2026 Review cycle: Annual or upon material change

Purpose

This policy describes the continuity and resilience approach used by GLS. The objective is to reduce the operational impact of platform disruption and to enable recovery within reasonable and predictable timescales.

Scope

This policy applies to production GLS environments and the data stored within them. It includes application services, databases, storage and supporting platform components.

Principles

  • Continuity should be designed into the platform
  • Backups must be restorable and periodically verified
  • Loss of a single component should not cause total outage
  • Customer data recovery must be prioritised
  • Business continuity goes beyond technical availability

Resilience controls implemented in GLS

Service resilience

GLS is deployed using modern cloud-native architecture designed to minimise the impact of localised component failure. Core services are monitored and restart automatically where appropriate.

Backups & recovery

Customer data is backed up on a scheduled basis. Backups are retained for a defined period and are stored separately from live services. Restoration procedures are tested and improved over time.

Isolation of tenants

Logical tenant separation reduces the risk that an issue affecting one customer impacts another.

Operational continuity

GLS aims to ensure that essential operational functions remain available wherever possible. In the rare event of platform outage, data submitted after service recovery is processed safely.

Incident response

In the event of significant disruption, GLS will prioritise:

  • restoration of service availability
  • integrity and recovery of customer data
  • communication with affected customers
  • root-cause analysis and prevention

Customer responsibilities

Customers remain responsible for their own organisational continuity plans, including local process workarounds and offline procedures. GLS forms part of a broader business continuity framework rather than replacing it.

Limitations

While systems are designed for resilience, no platform can guarantee zero disruption. Recovery times may vary depending on the nature and scale of the incident.

Review

This policy is reviewed at least annually, or sooner if material architectural or operational changes occur.