Company / Backup controls

Backup controls and the records that answer them

Most security frameworks ask that backups are kept, and that someone tests they restore. This page lists the controls an auditor is likely to ask about and the SafeGrd record you can show for each. Using SafeGrd does not make an organization compliant with any of these frameworks. Your auditor decides what evidence a control needs.

The records

RecordWhat it showsWhere to get it
Fire Drill recordEach drill: the snapshot restored, when, the tables, rows and file digests compared with the backup, and whether it passed. Each record is signed with Ed25519 and carries the hash of the one before it.The console’s Fire Drills tab, or safegrd history --json. Your auditor can check the chain offline (how).
Snapshot listEvery backup, its size, and the date its S3 Object Lock ends.The console’s Snapshots tab, or safegrd list on a host that can read the bucket.
Threat Shield eventsSnapshots marked anomalous because tables or most of the rows disappeared, and the last good snapshot kept locked.The console, and the alerts sent to your team.
Evidence PackThe drill records, snapshot retention and who holds each surface’s key in one signed file, with the control each item is evidence for.Scale plan. See a sample.
Vanta and DrataEach Fire Drill record sent to the platform as dated evidence, signed, with the link to verify it offline. Connected under Settings with the platform’s API token, which SafeGrd keeps sealed.Scale plan.

Every plan runs Fire Drills. The pricing page says how often, and how far the restore goes, on each plan.

Controls and records

The quoted text is the framework’s own, checked in October 2026. ISO/IEC 27001 is sold by ISO and not published free, so its control is described rather than quoted.

FrameworkControlWhat it asksRecord
SOC 2 (Trust Services Criteria)A1.3“The entity tests recovery plan procedures supporting system recovery to meet its objectives.” One point of focus is testing the integrity and completeness of backup data.Fire Drill record
ISO/IEC 27001:2022Annex A 8.13, Information backupBackup copies of information, software and systems are kept and regularly tested, following the organization’s backup policy.Snapshot list and Fire Drill record
HIPAA Security Rule45 CFR 164.308(a)(7)(ii)(A), Data backup plan“Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.”Snapshot list, and Fire Drill records comparing each restore’s digests with the backup
HIPAA Security Rule45 CFR 164.308(a)(7)(ii)(D), Testing and revision procedures“Implement procedures for periodic testing and revision of contingency plans.”Fire Drill record, for the restore tests. Revising the plan is yours.
CIS Controls v8Safeguard 11.5, Test Data Recovery“Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.”Fire Drill record, per database, directory or mailbox
DORA, Regulation (EU) 2022/2554Article 12(2)“Testing of the backup procedures and restoration and recovery procedures and methods shall be undertaken periodically.”Fire Drill record
NIS2, Directive (EU) 2022/2555Article 21(2)(c)“business continuity, such as backup management and disaster recovery, and crisis management”Snapshot list and Fire Drill record, for the backup part
GDPRArticle 32(1)(c)“the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident”Fire Drill record, with each restore’s duration
GDPRArticle 32(1)(d)“a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing”Fire Drill record, for the backups

What the records do not cover

To ask which record fits a control not listed here, write to support@safegrd.dev.