1. Home
  2. Wonder Security & Trust

Wonder Security & Trust

Resilience & Operations

Resilience & Operations

BackupsDisaster Recovery / Recovery ObjectivesLoggingMonitoringAdministrative Audit TrailIncident ResponseSLA / AvailabilityCapacity & Load Testing
Backups
Disaster Recovery / Recovery Objectives
Logging
Monitoring
Administrative Audit Trail
Incident Response
SLA / Availability
Capacity & Load Testing

Backups

Imagine's primary database is protected by automated MongoDB Atlas Cloud Backup, with backups maintained in the EU Central (Frankfurt) region.

BackupRetention
Snapshots every 6 hours7 days
Daily snapshots7 days
Weekly snapshots4 weeks
Monthly snapshots12 months
Yearly snapshots1 year
Point-in-time restore7-day restore window

File storage is protected separately through AWS S3 Versioning. Previous versions of stored objects are retained, allowing recovery from accidental modification or deletion.

File protectionConfiguration
Private file storageS3 Versioning enabled
Public file storageS3 Versioning enabled
Previous-version retentionNo automatic expiration policy currently configured

Disaster Recovery / Recovery Objectives

Imagine maintains recovery objectives supported by automated database backups, point-in-time recovery, file versioning, and managed cloud infrastructure.

Recovery controlConfiguration
Recovery Point Objective (RPO)≤ 1 hour
Recovery Time Objective (RTO)≤ 8 hours
Database recoveryMongoDB Atlas Cloud Backup with 7-day point-in-time restore
File recoveryAWS S3 Versioning
Recovery procedureIn progress
Recovery testingIn progress

Logging

Imagine maintains centralized application and security-event logging for operational monitoring and investigation.

ControlConfiguration
Application loggingProduction and Staging application logs are centralized in AWS CloudWatch Logs
Environment separationProduction and Staging use separate CloudWatch log streams
Application log retention7 days
Security audit eventsSelected security-sensitive actions are recorded with institution, user, IP, action and timestamp metadata
Log accessApplication and security logs are internal and are not exposed through the institutional user interface
Infrastructure access loggingAdditional infrastructure-level logging is being expanded

Status: Hardening in progress

Monitoring

Imagine uses platform health checks, cloud-provider metrics, and targeted operational alerts to monitor application and infrastructure behavior. Additional proactive monitoring and alerting controls are being expanded.

Monitoring areaCurrent configuration
Application healthAWS load balancer health checks monitor Production and Staging application targets
Infrastructure metricsAWS provides service-level metrics for ECS, load balancing, Lambda, S3, and Valkey
Application alertsTargeted operational failures are reported to the engineering/operations channel
File security monitoringAWS GuardDuty Malware Protection for S3 provides malware scan results for protected uploads
Proactive availability alertingHardening in progress
Infrastructure alarm coverageHardening in progress

Status: Hardening in progress

Administrative Audit Trail

Imagine records structured audit events for selected security-sensitive and administrative actions to support investigation and accountability. Audit coverage is being expanded across additional administrative actions.

AreaCurrently audited
User administrationUser deletion
Roles & permissionsPlatform role changes, course assignments, permission changes
Authentication & credentialsPassword changes and password-reset requests
Academic administrationSelected grade changes
Audit metadataInstitution, acting user, IP address, action and timestamp

Status: Hardening in progress

Incident Response

Imagine maintains a documented incident-response process for identifying, investigating, containing, and responding to Personal Data Breaches.

AreaProcess
Incident handlingIdentification, investigation, containment, and response
Breach notificationAffected institutions are notified without undue delay and no later than 48 hours after Imagine becomes aware of a Personal Data Breach
Incident informationRelevant information is provided as it becomes available to support the institution's own notification obligations
Investigation & remediationImagine reasonably cooperates with the institution's investigation and remediation

SLA / Availability

Imagine is designed to provide continuous availability for institutional teaching and learning, with a standard monthly availability target of 99.9%.

AreaCommitment
Availability target99.9% monthly
Planned maintenanceCommunicated at least 48 hours in advance where applicable
Availability calculationScheduled maintenance is excluded
External dependenciesSubject to applicable contractual exclusions for third-party service outages

Capacity & Load Testing

Imagine uses managed cloud infrastructure that can be scaled as institutional usage grows. Production capacity is monitored and infrastructure resources can be adjusted based on demand.

AreaCurrent configuration
Production computeAWS ECS Fargate
Current production capacity1 vCPU / 2 GB memory
Horizontal scalingSupported by the infrastructure; automatic ECS scaling is not currently enabled
Formal load testingTesting in progress

Status: Testing in progress

Privacy at WonderHow we process dataWonder Security & Trust|© 2026 Wonder. All rights reserved.