Field guidesHF-G-003Backups & recovery

Backups that actually restore: retention, replication, and point-in-time recovery

Daily snapshots, retention windows, and point-in-time recovery in plain words — and where Continuous Protection changes the arithmetic.

updated July 11, 20264 min read

You leave with

Your worst-case data loss under each strategy, and the one question that exposes any host’s backup theater.

Every host says the word “backups” with confidence. The questions that matter are quieter: how much can you lose, how far back can you reach, and when did anyone last prove a restore actually works? This guide walks the three dials — frequency, retention, and recovery point — in plain words, and shows where Continuous Protection changes the arithmetic.

The only number that matters: what you can lose

Engineers call it a recovery point objective. In plain words: if the disk died right now, how old is the freshest copy you could stand back up? With nightly backups the honest answer is “up to twenty-four hours old.” A site edited weekly shrugs at that. A site that has taken forty orders since 2 a.m. does not. Nothing about a backup plan matters more than making this number match what your site actually does between midnights.

Daily versus multi-daily

Daily is the floor for anything that deserves the name backup: a complete copy of files and database, taken every night, moved off the node that serves the site — because a copy that shares a disk with the original shares its fate. For most sites, daily is genuinely enough, and a host that insists otherwise is selling fear.

Multi-daily snapshots narrow the window: a copy every six hours turns a worst case of a day into a worst case of a quarter-day. But notice what does not change — there is always a gap, and everything inside the gap is exposure. Snapshots can shrink the window. Only replication closes it.

Retention: how far back you can reach

Frequency answers “how recent.” Retention answers “how far back” — and it is the dial people discover they needed only after something quiet goes wrong. Corruption is rarely loud. A plugin update mangles a table on Tuesday; nobody notices until Friday. If you keep only last night’s backup, every copy you own now contains the damage.

This is why retention comes in windows, not single copies. On our fleet the rhythm is nightly copies held for thirty days and weekly copies held for a quarter — deep enough that “we only just noticed” is a recoverable sentence instead of a eulogy.

StrategyWorst-case lossReaches backRight for
Nightly snapshotsUp to 24 hours30 days nightly, 90 days weeklyBrochure sites, portfolios, sites edited weekly
Multi-daily snapshotsA few hoursSame windows, denser near the presentBusy blogs, active membership sites
Continuous ProtectionSecondsAny minute inside the protection windowStores, bookings, anything earning between midnights
Three postures, honestly compared

What Continuous Protection adds

Continuous Protection is two mechanisms working together — and it is a protection feature, not a different kind of hosting. First, live replication: every change your site writes is streamed to a second node within seconds, so a hardware failure stops being a data event at all. Second, point-in-time restore: alongside the replica, a journal of changes is kept, which means a site can be rolled back to 14:32:07 — the minute before the bad deploy, the accidental deletion, the malformed import — instead of to whenever last night’s snapshot ran.

It ships included on Foundry and as an add-on to Ember and Forge. The test for whether it is worth it is unsentimental: does anything of value happen on your site between two backups? Orders, bookings, sign-ups, member posts. If yes, the gap between snapshots has a price, and Continuous Protection is what removes it.

A restore nobody has rehearsed is a rumor

The uncomfortable industry truth: backup systems fail silently, and the failure is discovered at the worst possible moment, because restoring is the only real test and almost nobody runs it. On the fleet, restore drills are routine — a real snapshot is brought back to life on a scratch node, timed, and checked. Does the database come up? Do the images load? Does the admin log in?

Whatever host you use — including us — you are owed a plain answer to one question: when did you last restore one? A confident answer names a date and a duration. Anything else is a description of hope.

None of this is exotic. Frequency, retention, replication — three dials, each answering a different bad day. Set them from the site’s real rhythm rather than from fear, rehearse the restore, and backups stop being an act of faith and become what they should have been all along: the most boring feature you own.

Filed under backups & recovery · HF-G-003

Still a question? Ask us — same-day answers.

The shortcut

Reading optional. Doing included.

Everything in this guide is work we do for clients every week — sizing, moving, protecting. Take a plan and it is simply handled, monitored 24/7 with same-day answers.