Resilience & recovery
Recover the service. Do not create a recovery backdoor.
VESTA treats recovery as a cryptographic and data-consistency problem, not simply as possession of another copy.
One coherent backup generation
Restoration is valid only when business data and cryptographic state agree.
For medical imaging, one VESTA generation binds the Pixience business snapshot, VESTA metadata, encrypted objects and the cryptographic recovery references required to restore them.
Business snapshot
Hash, schema, consistency point and backup reference.
VESTA snapshot
Ledger, lifecycle, revisions and policy references.
Encrypted objects
Every protected member required by the generation.
Crypto references
Versioned archives or references needed for recovery.
Generation manifest
Integrity evidence proving the complete coherent set.
Distributed recovery authority
No universal recovery key. No silent bypass.
Recovery uses an explicit quorum across protected locations and independent actors. The production path is not weakened to make disaster recovery easier.
Declare the event
Identify the target site, generation, scope, recovery purpose and authorized operators.
Verify coherence
Validate manifests, hashes, schema versions, object counts, revisions and cryptographic references.
Collect the quorum
Independent recovery contributors act through explicit governance and a fully audited process.
Restore and revalidate
Recovered business data, VESTA state and encrypted members are reconstructed and checked together.
Activate and supersede
The verified generation becomes active and obsolete states are explicitly superseded, never ambiguously reused.
Failure modes
Designed for operational failure, hostile compromise and cryptographic continuity.
A recovery design is credible only when the failures below are exercised against the complete stack.
Ransomware
Protected generations remain separable from a compromised production environment.
Site loss
Remote coherent copies support controlled reconstruction without relying on the lost site.
HSM unavailability
The system fails closed or follows an explicit time-bound continuity policy.
Metadata rollback
Generation, revision and integrity evidence expose stale or inconsistent state.
Partial backup
An incomplete generation never becomes a valid restore point.
Compromised recovery actor
No single participant can independently reconstruct the complete recovery authority.
A backup is not complete because files exist. It is complete only when the entire business and cryptographic state can be restored coherently.
Prove the restore path

