Company / Backup controls
Backup controls and the records that answer them
Most security frameworks ask that backups are kept, and that someone tests they restore. This page lists the controls an auditor is likely to ask about and the SafeGrd record you can show for each. Using SafeGrd does not make an organization compliant with any of these frameworks. Your auditor decides what evidence a control needs.
The records
| Record | What it shows | Where to get it |
|---|---|---|
| Fire Drill record | Each drill: the snapshot restored, when, the tables, rows and file digests compared with the backup, and whether it passed. Each record is signed with Ed25519 and carries the hash of the one before it. | The console’s Fire Drills tab, or safegrd history --json. Your auditor can check the chain offline (how). |
| Snapshot list | Every backup, its size, and the date its S3 Object Lock ends. | The console’s Snapshots tab, or safegrd list on a host that can read the bucket. |
| Threat Shield events | Snapshots marked anomalous because tables or most of the rows disappeared, and the last good snapshot kept locked. | The console, and the alerts sent to your team. |
| Evidence Pack | The drill records, snapshot retention and who holds each surface’s key in one signed file, with the control each item is evidence for. | Scale plan. See a sample. |
| Vanta and Drata | Each Fire Drill record sent to the platform as dated evidence, signed, with the link to verify it offline. Connected under Settings with the platform’s API token, which SafeGrd keeps sealed. | Scale plan. |
Every plan runs Fire Drills. The pricing page says how often, and how far the restore goes, on each plan.
Controls and records
The quoted text is the framework’s own, checked in October 2026. ISO/IEC 27001 is sold by ISO and not published free, so its control is described rather than quoted.
| Framework | Control | What it asks | Record |
|---|---|---|---|
| SOC 2 (Trust Services Criteria) | A1.3 | “The entity tests recovery plan procedures supporting system recovery to meet its objectives.” One point of focus is testing the integrity and completeness of backup data. | Fire Drill record |
| ISO/IEC 27001:2022 | Annex A 8.13, Information backup | Backup copies of information, software and systems are kept and regularly tested, following the organization’s backup policy. | Snapshot list and Fire Drill record |
| HIPAA Security Rule | 45 CFR 164.308(a)(7)(ii)(A), Data backup plan | “Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.” | Snapshot list, and Fire Drill records comparing each restore’s digests with the backup |
| HIPAA Security Rule | 45 CFR 164.308(a)(7)(ii)(D), Testing and revision procedures | “Implement procedures for periodic testing and revision of contingency plans.” | Fire Drill record, for the restore tests. Revising the plan is yours. |
| CIS Controls v8 | Safeguard 11.5, Test Data Recovery | “Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.” | Fire Drill record, per database, directory or mailbox |
| DORA, Regulation (EU) 2022/2554 | Article 12(2) | “Testing of the backup procedures and restoration and recovery procedures and methods shall be undertaken periodically.” | Fire Drill record |
| NIS2, Directive (EU) 2022/2555 | Article 21(2)(c) | “business continuity, such as backup management and disaster recovery, and crisis management” | Snapshot list and Fire Drill record, for the backup part |
| GDPR | Article 32(1)(c) | “the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident” | Fire Drill record, with each restore’s duration |
| GDPR | Article 32(1)(d) | “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing” | Fire Drill record, for the backups |
What the records do not cover
- Your backup policy, contingency plan and incident response plan. The records show the backups and the tests the plan calls for.
- Systems SafeGrd does not back up. A drill tests the databases, directories and mailboxes you added, not the application around them.
- How long a full recovery of your service takes. A drill times one restore, not bringing your service back.
To ask which record fits a control not listed here, write to support@safegrd.dev.