XTen.Deploy Start a health check →
✦✦✦

Have you ever actually restored your backup?

Most businesses running a web application have backups. Almost none have ever restored one. A backup you've never restored isn't a backup — it's a file of unknown contents, in a format nobody has checked, that you're betting the business on.

We check. Three business days. Fixed price. Written report either way.

$450 fixed · 46 published checks · a real restore test · three business days
Start a health check See all 46 checks
01 — What you get

A written answer to the question nobody can bluff

Not a scan. Not a dashboard. A person looks at your system against a published checklist, tries to restore your backup, and writes down what happened.

A real restore, performed

We take your most recent backup, restore it, and tell you whether it worked and how long it took. On your own test infrastructure with you watching, or on a throwaway instance we destroy afterwards. Your production system is never touched.

46 checks, every one evidenced

Backups, restore, access, patching, hosting, monitoring, continuity and data obligations. Rated Critical to Low. A check only passes with evidence — "the developer says it's handled" is not evidence.

A plan you can act on without us

A one-page summary for your board or owner, and a prioritised 90-day plan written so your own developer can execute it. You're under no obligation afterwards.

02 — The checklist

All 46 points, published before you buy

This is the entire scope of the engagement. We publish it because a checklist you can read is worth more than a promise you can't — and because a fair few people will read it, find the gap themselves and fix it without us. That's a good outcome too.

A · Backup coverage 10 checks
  1. A backup of the application database exists and is current.
  2. Uploaded files and user content are backed up — the most commonly missed item.
  3. Configuration is backed up: environment files, web server config, cron, certificates.
  4. Backups run automatically, not by someone remembering.
  5. A failed backup job reports its failure somewhere a human reads.
  6. Backups are stored off the machine being backed up.
  7. Backups are stored outside the hosting account, or in a separate security boundary.
  8. A retention policy exists and is enforced.
  9. Retention is long enough to survive slow corruption discovered weeks later.
  10. Backups are encrypted at rest, or demonstrably access-controlled.
B · Restore proof 5 checks
  1. A restore has been performed at any time in the system's life.
  2. A restore has been performed in the last 12 months.
  3. A written restore procedure exists that a second person could follow.
  4. The restore time is known — a measured number, not an estimate.
  5. We perform a live restore during the engagement and record the result.

Check 15 is the one that pays for the engagement. Everything else can be argued about. A restore either completed or it didn't, and we'll tell you which — with a time on it.

C · Access and credentials 6 checks
  1. A current list exists of who has access to the server, hosting, registrar, database and admin.
  2. Nobody who has left still has access.
  3. The domain and DNS sit in an account the business itself controls.
  4. Administrative access is individual, not a shared login.
  5. MFA is on the hosting account, the registrar and the application admin.
  6. Credentials have been rotated, and there is a procedure for when someone leaves.
D · Currency and patching 6 checks
  1. The operating system still receives security updates.
  2. The language runtime is on a supported version.
  3. The database engine is on a supported version.
  4. Dependencies have been updated since go-live, and somebody knows how.
  5. Security updates are applied on a schedule, not when something breaks.
  6. There is a way to find out that a vulnerability affects you.
E · Hosting and infrastructure 6 checks
  1. It is known and documented where the system runs and who the provider is.
  2. Hosting is paid from a business method, and renewal notices reach a monitored address.
  3. There is enough disk headroom that a log file cannot take the system down.
  4. TLS certificates renew automatically, and someone is told if renewal fails.
  5. The system starts cleanly after a reboot.
  6. A staging path exists to try a change before production — or it is honestly acknowledged that it doesn't.
F · Monitoring and alerting 4 checks
  1. Somebody or something is notified when the site goes down — not the customer.
  2. Application errors are logged somewhere durable and findable.
  3. Log retention is long enough to investigate an incident found a week later.
  4. There is a defined who-gets-called path for 6pm on a Friday.
G · Continuity and documentation 5 checks
  1. Documentation is sufficient for a competent stranger to run the system.
  2. Source code is in version control and the business can reach it.
  3. The business — not an individual — owns the code, accounts and data.
  4. The business knows the monthly running cost and what it is committed to.
  5. A recovery objective is stated: acceptable data loss, and acceptable downtime.
H · Data protection obligations 4 checks
  1. It is known what personal information the system holds, and about whom.
  2. Privacy Act and Notifiable Data Breaches obligations are understood, or advice is recommended.
  3. A breach response path exists: who is told, in what order, within what time.
  4. Payment or health data is handled by a compliant processor rather than stored in the application.
03 — Price and terms

Fixed, published, and half price if we find nothing

ItemDetail
Price$450, fixed. Not an estimate, no overrun risk. Invoiced on delivery, 7-day terms.
TimeThree business days from access being granted.
Your effortAbout 45 minutes — a short intake form, and read-only access.
AccessRead-only. We never ask for your passwords, your MFA codes, or production write access. Everything granted is listed in writing, and the last page of your report is the revocation checklist.
Your dataThe restore runs on your infrastructure where possible. Where it can't, we provision a single-purpose instance and destroy it within 24 hours, evidenced in the report. We retain no production data.
AfterwardsNo obligation. The report is yours whether or not you ever buy anything else.

If we find nothing serious, you pay $225.

If the report contains no Critical and no High finding, we halve the fee. We haven't yet looked at a system that came back clean — but if yours does, you shouldn't be paying full freight to be told so.

And if you start a Care & Hosting plan with us within 30 days of the report, $150 of the fee comes back against your first invoices.

04 — Questions

The ones people actually ask

Why would I give a stranger access to my systems?
Mostly, you don't. Our preferred path is that you run the commands we send and return the output — zero access granted. Where access is needed it's read-only, it's enumerated in writing, and you revoke it the day the report lands. We never accept production write access, personal passwords or MFA codes.
$450 for a document?
It's $450 for one number you don't currently have: whether your backup restores, and how long it takes. If it does, you've bought certainty for less than a day of a developer's time. If it doesn't, you've found out on a Tuesday of your choosing rather than a Sunday of someone else's.
Our host handles backups.
They back up their infrastructure to protect their platform. Read your agreement — very few warrant that your application is restorable, and none will restore it for you on a Sunday. Send us the agreement and we'll read it with you before you buy anything.
You're new. Where are your case studies?
We're new to selling this and we say so on our website. That's exactly why the checklist is published before you pay, why the price is fixed so you carry no overrun risk, and why you pay half if we find nothing serious. We've also run this check on our own production systems and published the result — including the checks we failed.
Can you just fix it instead?
Not until we know what's wrong. Quoting a fix without looking is how you get the estimate that doubles. The check is the quoting process — and $150 of it comes back if you go onto a Care plan.
We'd rather do it ourselves.
Good — you should, and the checklist above is yours for free. If you get to check 15 and can't do the restore test, that's when to call us. Genuinely.
Is this a penetration test or a security audit?
No. It's an operational resilience review — backups, restore, access, patching, continuity. It isn't a penetration test, a code review, an audit against a formal standard, or legal advice. Where we identify a legal obligation we say what it is and recommend you take advice.
05 — Start

Tell us about your system

Two minutes. We'll come back within one business day with a confirmed scope and the intake form. No obligation, and we'll tell you honestly if you don't need this.

We'll only use these details to answer your enquiry. See our Privacy Policy. No newsletter, no list.