Disaster Recovery and High Availability
Recovery that runs itself.No human in the loop.
Application-level, cross-cloud failover for regulated industries, built into the Sovereign Cloud Platform and deployed on infrastructure you own.
Where Public Cloud DR Fails
Your DR tool recovers machines. Your operation runs on applications.
Public cloud DR restores VMs and leaves your team to restart services by hand, in the right order, at 3am. For a regulated institution that gap is a compliance exposure, not an inconvenience.
When critical systems fail, every second costs money, reputation and regulatory standing. VM-level recovery brings the infrastructure back but not the running application: your namespaces, dependencies, stateful sets, config and secrets still have to be brought up in sequence, by an operator, under pressure. When the incident spans two clouds, and eventually it will, that manual choreography is exactly what a resilience test is designed to expose.
The application recovery gap
VM recovery restores the machine, not the workload. After failover your team still has to identify which services failed, in what order they depend, and why, while the clock runs.
A regulator-ready gap
DORA, NIS2 and BAFIN require tested, documented ICT continuity with defined recovery objectives. A DR tool that cannot produce an audit trail of its RTO and RPO performance is a compliance gap your next supervisory review will surface.
Multi-cloud reality
Your workloads span multiple public clouds and on-premises. Most DR tools cover one. When an incident crosses two environments, you are orchestrating failover by hand across systems the tool was never built to coordinate.
A sovereignty violation
Many public cloud DR services route orchestration through a foreign-controlled control plane, a structural sovereignty breach for a regulated institution that cannot outsource control.
Core Capabilities
Application-level recovery, across every cloud you run.
The Sovereign Cloud Platform recovers running applications, not bare machines, and orchestrates failover, backup and recovery across every cluster and cloud you operate.
Application-level recovery
The platform operates at the container workload level. It recovers namespaces, deployments, stateful sets, services, config maps, secrets and persistent volumes, in dependency order, to a running, verified application state, not a raw machine image.
Cross-cluster and cross-cloud failover
Automated failover across clusters in one cloud, between clouds, or across on-premises data centers. Active-Active and Active-Standby topologies are both supported, with real-time health monitoring and configurable eviction tolerances.
Configurable, auditable RTO and RPO
Cluster monitoring intervals, unhealthy grace periods and eviction timeouts are tunable to core-banking and government SLAs. Every parameter is auditable and reportable to a regulator.
Automated detection and failover
No human in the loop. When a cluster crosses the unhealthy threshold it is tainted automatically, eviction begins, and workload pods migrate to healthy clusters without operator intervention.
Full backup suite
Two failure modes, one suite: a single service failing in production, and a full cluster event. The platform handles both.
- Namespace-level backups with label filtering for surgical service recovery.
- Scheduled incremental and full backups for cluster-level continuity.
- Every backup verifiable and restorable to a clean application state.
Multi-region high availability
Purpose-built for geo-distributed deployment across availability zones and regions, meeting both technical HA targets and regulatory mandates for geographic data separation.
Architecture at a Glance
A hub-and-spoke model, deployed on your infrastructure.
The Sovereign Cloud Platform runs disaster recovery on a hub-and-spoke multi-cloud management model, with the control plane on your own ground.
Global Control Plane
A unified management cluster handles cross-cloud workload scheduling, failover policy and health monitoring, deployed on your infrastructure.
Member Clusters
Production, standby and DR clusters in any cloud or on-premises environment register as managed members. Aggregated or dynamic-weight scheduling policies govern normal operations.
Failover Engine
A continuous ClusterMonitor polls every registered cluster. On unhealthy detection beyond the grace period it taints the cluster, drains pods by graceful eviction, and reschedules to healthy clusters on remaining capacity.
Backup Controller
A scheduled backup controller persists full and incremental snapshots of application namespaces and etcd state to your own storage backend: S3-compatible, on-prem NFS, or a private object store.
Recovery Orchestrator
Namespace-level restore with label-selector filtering enables surgical recovery of a single service without touching adjacent workloads, minimizing blast radius and recovery time.
Deployed on your infrastructure, with no mandatory call-home to Amanah.
Regulator-Ready by Design
Built to pass the supervisory review.
Resilience is only worth what you can prove. The Sovereign Cloud Platform produces the tested, documented, sovereign evidence that European financial and critical-infrastructure regulators now demand.
DORA
Tested, documented ICT continuity with defined recovery objectives and a full audit trail of RTO and RPO performance, the evidence a financial-sector resilience test is built to check.
NIS2
Continuity for essential and important entities, with automated failover and geographic separation that hold critical services up through a regional event.
BAFIN
Recovery objectives, backup regimes and failover drills that are configurable, repeatable and reportable to a financial supervisor on demand.
EU 8-Pillar Sovereignty
The full European sovereignty framework, independently certified and enforced across every recovery domain, with the control plane on your own soil.
Governed by your laws. Operated by your people. Sovereign at every layer.
Proven, Not Theater
Continuity built for the 3am incident.
The stack behind the Sovereign Cloud Platform carries more than a thousand production references across 17 countries and twenty industries.
Full EU 8-pillar sovereignty, independently certified and enforced across every recovery domain.
No control traffic is required to leave your infrastructure. Recovery runs even when the outside world does not.
No DR Theater
Regulated institutions cannot afford DR theater, tools that demo well and then fail the sovereignty test, the audit test, or the 3am production incident. The Sovereign Cloud Platform was built by the engineers who maintain cloud-native infrastructure, for institutions that cannot afford to get recovery wrong.
Your Vision. Your Stack. Your Control. Your Intelligence. Our Knowhow Transfer.
Map your DR posture against DORA and NIS2.
We will map your current DR posture against DORA and NIS2, identify your sovereignty gaps, and show you exactly how the Sovereign Cloud Platform closes them, on your infrastructure, on your timeline.
Your data stays in your environment. We map your posture before anything is deployed.


