Purpose
This policy describes the continuity and resilience approach used by GLS. The objective is to reduce the operational impact of platform disruption and to enable recovery within reasonable and predictable timescales.
Scope
This policy applies to production GLS environments and the data stored within them. It includes application services, databases, storage and supporting platform components.
Principles
- Continuity should be designed into the platform
- Backups must be restorable and periodically verified
- Loss of a single component should not cause total outage
- Customer data recovery must be prioritised
- Business continuity goes beyond technical availability
Resilience controls implemented in GLS
Service resilience
GLS is deployed using modern cloud-native architecture designed to minimise the impact of localised component failure. Core services are monitored and restart automatically where appropriate.
Backups & recovery
Customer data is backed up on a scheduled basis. Backups are retained for a defined period and are stored separately from live services. Restoration procedures are tested and improved over time.
Isolation of tenants
Logical tenant separation reduces the risk that an issue affecting one customer impacts another.
Operational continuity
GLS aims to ensure that essential operational functions remain available wherever possible. In the rare event of platform outage, data submitted after service recovery is processed safely.
Incident response
In the event of significant disruption, GLS will prioritise:
- restoration of service availability
- integrity and recovery of customer data
- communication with affected customers
- root-cause analysis and prevention
Customer responsibilities
Customers remain responsible for their own organisational continuity plans, including local process workarounds and offline procedures. GLS forms part of a broader business continuity framework rather than replacing it.
Limitations
While systems are designed for resilience, no platform can guarantee zero disruption. Recovery times may vary depending on the nature and scale of the incident.
Review
This policy is reviewed at least annually, or sooner if material architectural or operational changes occur.