Angles for SAP SaaS - Backup and Disaster Recovery Management - Overview
This document provides an overview of how insightsoftware protects the Angles for SAP SaaS service through its backup and recovery processes, the independent audits and assessments performed to validate these controls, and the methods available for obtaining the evidence required to support your assurance process requires.
Audience
Customer IT operations and information security teams for Angles for SAP from insightsoftware, SaaS deployment.
Purpose
Your IT operations team is responsible for the resilience of every system in your environment, including cloud services like Angles for SAP. This document explains how:
- insightsoftware protects your data through backup and recovery
- our procedures are independently verified, and
- to access the evidence you need for your compliance processes
Following sections describes our controls, and the standards they meet, while intentionally excluding implementation details that could compromise security. If you need more specific information, section Requesting Further Detail explains how to access it securely.
Our Compliance Position
We maintain a comprehensive information security management system (ISMS) that covers every aspect of how we develop, operate, and deliver Angles for SAP from initial development through day-to-day infrastructure management and service delivery.
SOC 2Type2
insightsoftware completes annual soc 2 Type 2 audits. A Type 2 audit is not a questionnaire or a self-assessment. An independent accounting firm examines both the design of our internal controls and their operating effectiveness across a defined observation period, and issues an opinion on the results. Backup and disaster recovery controls fall within that examination.
ISO 27001
Specific insightsoftware products and services also meet the ISO 27001 standard for information security management systems.
Annual Cadence
These audits repeat every year. A control that worked once does not satisfy a Type 2 examination; it has to keep working, and the evidence has to keep being produced.
Both positions are published on our public Trust and Security Page
What soc 2 Requires of Backup and Recovery
SOC 2 is built on the AICPA Trust Services Criteria. Where the Security category is mandatory, the Availability category is the one that governs backup and disaster recovery, and it is the category most relevant to the questions IT operations teams ask.
| Criterion | What IT Requires |
| AI.1 | The organization maintains and monitors capacity to meet its availability objectives. |
| AI.2 |
The organization designs, implements, and operates backup processes and recovery infrastructure to meet its availability objectives. |
| AI.3 | The organization tests its recovery procedures. Documented procedures alone are not sufficient evidence; the test has to happen and the results have to be recorded. |
The Common Criteria add further obligations that apply here, including recovery from security incidents and the assessment and mitigation of risks arising from business disruption.
Important: An auditor will not accept a disaster recovery plan as evidence that recovery works. They ask for the results of an exercise. That requirement is what drives the testing commitment in section How Recovery Works, and it is the reason a SOC 2 Type 2 report is a stronger assurance artifact than a vendor's own description of its procedures.
Source:
- SOC suite of services - overview
- SOC 2: Trust Services Criteria - topic page
- 2017 Trust Services Criteria, with revised points of focus, 2022
How the Service Is Backed Up
Angles for SAP SaaS runs on Amazon Web Services. Backup is handled by managed AWS backup services rather than by scripts or manual procedures, and it is provisioned automatically as part of building each customer environment. No step in the backup path depends on someone remembering to run it.
Automated and daily: Every customer environment is backed up on an automated daily schedule. This covers the application and integration servers, the transactional database, and the analytics data store. Each of these has a backup path appropriate to the technology behind it, and all of them run to a schedule without operator involvement.
Layered retention: Daily backups are supported by additional periodic recovery points retained over longer horizons, including long-term archival storage. This means recovery is not limited to the last 24 hours, older recovery points remain available for a substantial period.
Encrypted: Backup data is encrypted at rest, and all data in transit is protected with strong TLS encryption. Encryption keys are managed through the cloud provider's managed key service.
Isolated per customer: Each customer environment has its own backup store. Recovery points for one customer are not commingled with another's, and access to them is separately controlled.
Monitored: Backup execution is monitored, and configuration is captured as part of the evidence set reviewed during our annual audit.
How Recovery Works
insightsoftware has moved Angles for SAP SaaS recovery from a documented manual procedure to a fully automated, single-workflow restore. The characteristics below are the ones that matter to an IT operations audience assessing whether a recovery procedure is trustworthy.
| One procedure, not a collection of steps | A full environment restore - servers, transactional database, analytics database, and environment configuration - runs as one orchestrated operation. Recovery does not depend on an engineer correctly executing a long sequence by hand under pressure. |
| Plan before apply | Every restore is preceded by a read-only planning pass that reports exactly what will change before anything is written. Operators review that plan first. A restore cannot be executed without it. |
| Verified before it runs | The automation validates its own inputs before touching anything. It confirms that every recovery point exists, that it belongs to the intended customer, and that it is the correct type of artifact for the role it is being restored into. Any check that does not pass stops the operation rather than proceeding on an assumption. This is the control that prevents one customer's data from ever being restored into another customer's environment. |
| Authorized and gated | Executing a restore requires human approval from a named reviewer. The automation runs under a dedicated, least-privilege identity that holds only the permissions the restore itself needs, and that identity is used for nothing else. |
| Fully audited | Every restore produces a complete, immutable record: who requested it, who approved it, what was restored, from which recovery point, and the outcome of every stage. Credentials and secret values never appear in that record. |
| Reversible | The automation preserves the pre-restore state rather than overwriting it, and every resource it creates is tagged for identification. A restore that does not produce the expected result can be reversed. |
| Validated on completion | The restore concludes with automated health checks and reports the point in time the environment was recovered to, so the result can be confirmed against the recovery point that was requested rather than assumed. |
Recovery Testing
Documented procedures are not evidence. Testing is.
insightsoftware tests recovery procedures for Angles for SAP SaaS at least annually, as part of the control environment assessed in our annual SOC 2 Type 2 audit. Testing exercises the restore procedure itself rather than reviewing it on paper, and it is performed in an isolated environment so that live customer environments are never placed at risk by a test.
Each test is documented. Findings feed directly back into the recovery procedure and the automation that executes it, which is how the procedure improves between audit periods rather than only after an incident.
Test results form part of the evidence reviewed by our auditors. Customers who need to see evidence of testing should request the SOC 2 Type 2 report through the channel in section Requesting Further Detail - the report is the assurance artifact designed for exactly that purpose, and it carries an independent opinion that a document like this one cannot.
Requesting Further Detail
Some information the IT operations team may want like retention periods, recovery objectives, control listings, and audit evidence, is available below the level of detail insightsoftware publishes openly. That information is available through a channel built for it.
INSIGHTSOFTWARE TRUST CENTER
The trust center is our self-service portal for security and compliance documentation. Through it you can request the SOC 2 type 2 report and supporting security documentation, typically under a non-disclosure agreement. Requests are reviewed by our information security team.
For anything the Trust Center does not cover, contact your insightsoftware account manager or customer success manager, who will route the request to the right team. Security questionnaires are welcome through the same route.
FAQs
| Question | Answer |
|
Is Angles for SAP SaaS backed up? |
Yes. Automated daily backups of every customer environment, encrypted and isolated per customer. |
|
How far back can it be recovered? |
Beyond the most recent day. Layered retention provides periodic recovery points over longer horizons, including long-term archival. |
| How is it restored? | Through a single automated, approval-gated workflow with pre-execution validation, full audit trail, and a preserved rollback path. |
| Is recovery tested? | Yes, at least annually, documented, and within the scope of our soc 2 Type 2 audit. |
| Who verifies this? | An independent accounting firm, annually, against the AICPA Trust Services Criteria. |
| How do we get the evidence? | Request the SOC 2 Type 2 report through the insightsoftware Trust Center. |