Skip to content
aicial
Legal

Business Continuity and Disaster Recovery Statement

Version: 1.0

Effective date: 19 August 2026

Last reviewed: 19 August 2026

This Business Continuity and Disaster Recovery Statement explains how Aperim Pty Ltd, which operates the aicial brand, keeps aicial’s services available, protects the data within them, and responds when something affects that availability.

1. About this statement

Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this statement, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; and “you” refers to a customer, prospective customer or other reader of this statement.

This statement applies to the aicial website and to our services — currently the Social Performance Audit, the Outcome-Proof Pack and the Benchmark & Strategy Engagement, and in future our planned self-serve software service once it becomes available. It describes the practical steps we take to keep those services available, protect the data within them, and respond when something affects that availability. This statement describes our practices; it is not itself a warranty, guarantee or contractual service-level commitment.

2. Our infrastructure approach

aicial’s infrastructure runs entirely on Cloudflare’s global network. Cloudflare Workers runs our application logic, Cloudflare D1 is our database, Cloudflare Turnstile protects our forms from bot and abuse activity, and we send transactional email through Cloudflare’s own Email Service, not a third-party email provider. We do not operate our own data centre or physical server infrastructure.

Building on a global network rather than a single facility gives our application layer inherent geographic distribution: Cloudflare operates data centres across many regions and jurisdictions, and Cloudflare Workers is designed to run our application logic from that distributed network rather than a single physical location. This gives that layer of our services a degree of resilience against a localised failure — an outage affecting a single data centre, for example — without us needing to design, build or maintain a disaster-recovery facility of our own.

Our database does not share that same distribution today. Cloudflare D1 keeps our primary database in a single location rather than replicating it live across regions, so a sustained failure affecting that location would affect our ability to serve data until it is resolved. We rely on the point-in-time recovery capability described in section 3 to recover from that kind of event, rather than on an already-available copy of the database elsewhere. We remain responsible for how we configure, operate and monitor the services we build on Cloudflare’s platform.

Running entirely on one provider also concentrates a real risk: a sustained outage or service interruption at Cloudflare would affect the availability of aicial’s own services, and that risk sits outside our control. We accept that trade deliberately — for a company at our stage, the resilience, security and operational simplicity a single well-resourced platform gives us outweighs the alternative of building, securing and operating our own multi-vendor infrastructure.

3. Data backups

Cloudflare D1, our database, includes a point-in-time recovery capability that is always on and does not depend on us triggering or remembering to take a backup. It lets us restore our production database to a specific point in time within a rolling window, currently up to 30 days, so we can recover from accidental data loss, corruption or an operational error affecting our primary database.

This recovery window is consistent with our Data Retention & Deletion Policy, which sets out how it interacts with our retention and deletion practices. Recovery is limited to that rolling window: we cannot recover data from further back than the window reaches, and this capability does not protect against an event that affects the recovery mechanism itself. If we bring additional backup infrastructure into use as our services develop, we will update this section to describe it.

4. Monitoring and outage response

Cloudflare’s platform gives us observability into our services, including error and request telemetry, that we can use to investigate an issue. Where that telemetry, or a report from you, brings a service issue to our attention, we investigate and act to restore normal service as quickly as reasonably possible, prioritised by its impact on customers.

Our Service Level Agreement sets out our specific uptime commitment and the service credits that apply if we do not meet it, and will govern our planned self-serve software service once it reaches general availability. This statement describes our operational practice for responding to an issue; it is the Service Level Agreement, not this statement, that sets out the contractual commitment.

5. Incident communication

Where an incident materially affects the availability of our services, we make reasonable efforts to tell affected customers about it, proportionate to the incident’s severity. Depending on the incident, we may do this through the service itself, by email, or through a published status update.

Where practical, we aim to say what we know, what we do not yet know, and what we are doing about it, and to follow up once the incident is resolved.

6. Business continuity and governance

Business continuity is broader than the service infrastructure covered in section 2. We maintain access to the business records and systems we rely on to keep operating and communicating with customers — including contracts, financial and billing records, and customer communications — in a way that does not depend entirely on any single business-administration tool or vendor remaining available.

Accountability for business continuity and disaster recovery sits with Aperim Pty Ltd’s leadership today. As the company grows, we will formalise these practices — clearer internal roles, a documented recovery plan and regular testing — proportionate to that growth, and we will update this statement when we do.

7. Review of this statement

We review this statement at least once a year, and sooner if we experience a significant incident affecting the availability of our services or materially change our infrastructure. The version, effective date and last-reviewed date shown at the top identify the current version. We publish the updated statement on our website and, where a change is material, provide additional notice through the service or by email before it takes effect.

8. Contact us

For questions about this statement, or to report an issue affecting the availability of our services, contact:

Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: compliance@aicial.com