Wonder Security & Trust
Resilience & Operations
Backups
Imagine's primary database is protected by automated MongoDB Atlas Cloud Backup, with backups maintained in the EU Central (Frankfurt) region.
| Backup | Retention |
|---|---|
| Snapshots every 6 hours | 7 days |
| Daily snapshots | 7 days |
| Weekly snapshots | 4 weeks |
| Monthly snapshots | 12 months |
| Yearly snapshots | 1 year |
| Point-in-time restore | 7-day restore window |
File storage is protected separately through AWS S3 Versioning. Previous versions of stored objects are retained, allowing recovery from accidental modification or deletion.
| File protection | Configuration |
|---|---|
| Private file storage | S3 Versioning enabled |
| Public file storage | S3 Versioning enabled |
| Previous-version retention | No automatic expiration policy currently configured |
Disaster Recovery / Recovery Objectives
Imagine maintains recovery objectives supported by automated database backups, point-in-time recovery, file versioning, and managed cloud infrastructure.
| Recovery control | Configuration |
|---|---|
| Recovery Point Objective (RPO) | ≤ 1 hour |
| Recovery Time Objective (RTO) | ≤ 8 hours |
| Database recovery | MongoDB Atlas Cloud Backup with 7-day point-in-time restore |
| File recovery | AWS S3 Versioning |
| Recovery procedure | In progress |
| Recovery testing | In progress |
Logging
Imagine maintains centralized application and security-event logging for operational monitoring and investigation.
| Control | Configuration |
|---|---|
| Application logging | Production and Staging application logs are centralized in AWS CloudWatch Logs |
| Environment separation | Production and Staging use separate CloudWatch log streams |
| Application log retention | 7 days |
| Security audit events | Selected security-sensitive actions are recorded with institution, user, IP, action and timestamp metadata |
| Log access | Application and security logs are internal and are not exposed through the institutional user interface |
| Infrastructure access logging | Additional infrastructure-level logging is being expanded |
Status: Hardening in progress
Monitoring
Imagine uses platform health checks, cloud-provider metrics, and targeted operational alerts to monitor application and infrastructure behavior. Additional proactive monitoring and alerting controls are being expanded.
| Monitoring area | Current configuration |
|---|---|
| Application health | AWS load balancer health checks monitor Production and Staging application targets |
| Infrastructure metrics | AWS provides service-level metrics for ECS, load balancing, Lambda, S3, and Valkey |
| Application alerts | Targeted operational failures are reported to the engineering/operations channel |
| File security monitoring | AWS GuardDuty Malware Protection for S3 provides malware scan results for protected uploads |
| Proactive availability alerting | Hardening in progress |
| Infrastructure alarm coverage | Hardening in progress |
Status: Hardening in progress
Administrative Audit Trail
Imagine records structured audit events for selected security-sensitive and administrative actions to support investigation and accountability. Audit coverage is being expanded across additional administrative actions.
| Area | Currently audited |
|---|---|
| User administration | User deletion |
| Roles & permissions | Platform role changes, course assignments, permission changes |
| Authentication & credentials | Password changes and password-reset requests |
| Academic administration | Selected grade changes |
| Audit metadata | Institution, acting user, IP address, action and timestamp |
Status: Hardening in progress
Incident Response
Imagine maintains a documented incident-response process for identifying, investigating, containing, and responding to Personal Data Breaches.
| Area | Process |
|---|---|
| Incident handling | Identification, investigation, containment, and response |
| Breach notification | Affected institutions are notified without undue delay and no later than 48 hours after Imagine becomes aware of a Personal Data Breach |
| Incident information | Relevant information is provided as it becomes available to support the institution's own notification obligations |
| Investigation & remediation | Imagine reasonably cooperates with the institution's investigation and remediation |
SLA / Availability
Imagine is designed to provide continuous availability for institutional teaching and learning, with a standard monthly availability target of 99.9%.
| Area | Commitment |
|---|---|
| Availability target | 99.9% monthly |
| Planned maintenance | Communicated at least 48 hours in advance where applicable |
| Availability calculation | Scheduled maintenance is excluded |
| External dependencies | Subject to applicable contractual exclusions for third-party service outages |
Capacity & Load Testing
Imagine uses managed cloud infrastructure that can be scaled as institutional usage grows. Production capacity is monitored and infrastructure resources can be adjusted based on demand.
| Area | Current configuration |
|---|---|
| Production compute | AWS ECS Fargate |
| Current production capacity | 1 vCPU / 2 GB memory |
| Horizontal scaling | Supported by the infrastructure; automatic ECS scaling is not currently enabled |
| Formal load testing | Testing in progress |
Status: Testing in progress