TRUST CENTRE · ASSURANCE STANDARD

Service Resilience & Recovery Objectives

PUBLIC ASSURANCELast updated: September 2026PCL OneVersion 1.0
Scope: PCL One municipal cloud production services
Baseline Commitment

For the Canadian municipal cloud baseline: 99.9% monthly production availability, Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 1 hour, supported by encrypted backups, geographically separate Canadian recovery and at least annual recovery exercises.

Service objectives

Service objectives table
MeasureBaseline objectiveMeaning
Monthly production availability99.9%Measured under the applicable SLA and service-schedule rules.
Recovery Time Objective (RTO)4 hoursTarget time to restore the production service following a declared disaster or major recovery event.
Recovery Point Objective (RPO)1 hourMaximum targeted data-loss window for the production service following a declared recovery event.
Severity 1 acknowledgement15 minutes, 24x7Target acknowledgement for a production-critical incident under the managed support model.

Resilience design baseline

  • Automated encrypted backups with point-in-time recovery capability.
  • For Canada-only municipal deployments, geographically separate recovery capability is maintained within approved Canadian regions, with production, backup and recovery data remaining in Canada.
  • Monitoring across service health, integrations, queues, certificates, backup outcomes and security events.
  • Documented recovery runbooks and controlled restoration/failover procedures.
  • Periodic restore testing and at least annual disaster-recovery/recovery exercise with measured outcomes and tracked corrective actions.

How RTO and RPO are applied

RTO and RPO apply to a declared service-recovery scenario affecting the production platform. They are recovery objectives, not a promise that every individual support ticket or third-party integration issue will be resolved within the same period. Dependencies outside PCL One’s control—such as a customer identity provider, telecommunications provider or customer-managed integration endpoint—are coordinated through the incident process and documented in the service design.

Operational assurance records

Operational assurance records table
Evidence streamWhat is recordedTypical delivery
Service reportAvailability, incidents, SLA attainment, changes and problem statusMonthly after service activation
Backup / restoreBackup success, material exceptions, restore-test result and corrective actionsAt agreed operational cadence
Recovery exerciseScenario, measured recovery time/data point, gaps, owners and closure actionsAt least annually
Material incident reportTimeline, impact, containment, recovery and corrective/preventive actionsFollowing material incidents

Applicability

This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.

Explore more assurance standards

Related customer-facing commitments

INCIDENT RESPONSE

Security Incident & Breach Notification

How material security incidents are assessed, communicated and followed through to resolution.

RECORDS LIFECYCLE

Data Retention, Backup & Secure Disposal

How customer records, backups and lifecycle disposal are governed.

VENDOR ACCESS MODEL

Privileged Support & Break-Glass Access

How elevated support access is approved, constrained, logged and reviewed.

Canadian Municipal Expertise|
ERP Implementation Capability|
PSAB-Aware Delivery|
Canadian Data Residency
Utility Billing · Property Tax · Permitting · Licensing · Asset Management · Work Orders