Resilience & recovery
Targets we drill against, not slogans
A platform that touches money has to fail well. We publish recovery targets per surface tier, the cadence we drill them at, and the outcome of the most recent drill. Anything missed lands on the trust ledger the same day.
Ledger RTO
≤ 15 min
RPO 0 · synchronous
Payouts RPO
≤ 60 s
HSM + dual bank rails
Drill cadence
Monthly
Per tier, rotating surfaces
Last full game day
2026-06-08
Findings on /tabletops
Recovery targets by tier
| Tier | RTO | RPO |
|---|---|---|
| Tier 0 · Ledger | ≤ 15 min | 0 (synchronous replication) |
| Tier 1 · Payouts | ≤ 30 min | ≤ 60 s |
| Tier 1 · Platform APIs | ≤ 30 min | ≤ 60 s |
| Tier 2 · Recon & pacing | ≤ 2 h | ≤ 5 min |
| Tier 3 · Reporting | ≤ 8 h | ≤ 1 h |
Regional posture
- Primary region EU-West with hot standby in EU-North; failover is automated and tested monthly.
- HK region is hot-active for APAC payouts with paired EU read replica for ledger continuity.
- Cross-region traffic shifting via DNS + service mesh; tested under load on every game day.
If we miss a target
- Customer notification within 1 hour of detection; incident report within 5 business days.
- Automatic SLA credits where the breach maps to /service-levels; visible in /service-credits.
- Root cause and remediation owner posted to /trust-ledger and /transparency.