Compliance

Korven One Business Continuity & Disaster Recovery Plan

Korven One is committed to maintaining operational resilience and ensuring continuity of critical services during disruptive events. This Plan establishes the framework used to prepare for, respond to, recover from, and mitigate operational disruptions affecting Korven One systems, services, customers, partners, and financial operations.

Last updated: Version 1.0 Draft · Effective Date: To Be Determined

1. Purpose

Korven One is committed to maintaining operational resilience and ensuring continuity of critical services during disruptive events. This Business Continuity and Disaster Recovery Plan (BCDR) establishes the framework used to prepare for, respond to, recover from, and mitigate operational disruptions affecting Korven One systems, services, customers, partners, and financial operations.

2. Scope

This Plan applies to:

  • Payment Infrastructure
  • Wallet Infrastructure
  • Merchant Services
  • Developer Platform
  • Treasury Operations
  • Settlement Operations
  • Remittance Services
  • Cloud Infrastructure
  • Employees
  • Contractors
  • Critical Vendors
  • Banking Partners

3. Objectives

Korven One aims to:

  • Protect customer funds
  • Maintain critical operations
  • Restore services quickly
  • Minimize financial losses
  • Protect customer data
  • Maintain regulatory readiness
  • Preserve customer trust

4. Business Continuity Principles

Korven One follows the following principles:

  • Operational Resilience
  • Customer Protection
  • Data Integrity
  • Service Availability
  • Rapid Recovery
  • Risk Reduction
  • Continuous Improvement

5. Critical Business Functions

The following functions are considered critical:

Tier 1 Critical

  • Payment Processing
  • Ledger Operations
  • Wallet Balances
  • Treasury Operations
  • Settlement Processing
  • Authentication Systems

Tier 2 Important

  • Merchant Dashboard
  • Developer Portal
  • Analytics
  • Reporting

Tier 3 Non-Critical

  • Marketing Website
  • Blog
  • Documentation Portal

Recovery priorities shall follow this classification.

6. Recovery Objectives

Recovery Time Objective (RTO)

Maximum acceptable downtime:

  • Tier 1: 4 Hours
  • Tier 2: 24 Hours
  • Tier 3: 72 Hours

Recovery Point Objective (RPO)

Maximum acceptable data loss:

  • Financial Systems: 15 Minutes
  • Operational Systems: 1 Hour
  • Non-Critical Systems: 24 Hours

7. Incident Activation

This Plan may be activated when events significantly impact:

  • Availability
  • Security
  • Financial Operations
  • Customer Access
  • Treasury Operations

Activation authority may be assigned to executive leadership or designated response teams.

8. AWS Cloud Outage Response

In the event of a major AWS disruption, Korven One may:

  • Activate secondary recovery procedures
  • Failover critical services where available
  • Prioritize payment and ledger services
  • Communicate service status updates

Critical systems should be designed for high availability where feasible.

9. Database Corruption Response

If database corruption occurs, Korven One may:

  • Isolate affected systems
  • Suspend impacted operations
  • Restore verified backups
  • Validate ledger integrity
  • Perform reconciliation reviews

Recovery actions shall be documented.

10. Datacenter Failure Response

If a datacenter becomes unavailable, Korven One may:

  • Activate backup infrastructure
  • Redirect traffic
  • Restore critical services
  • Verify transaction integrity

Priority shall be given to customer fund protection.

11. Cyberattack Response

Examples:

  • Unauthorized Access
  • Malware
  • DDoS Attacks
  • Infrastructure Compromise

Korven One may:

  • Isolate affected systems
  • Restrict access
  • Activate incident response procedures
  • Increase monitoring
  • Notify relevant stakeholders

12. Ransomware Response

In the event of ransomware, Korven One may:

  • Disconnect affected systems
  • Preserve forensic evidence
  • Restore clean backups
  • Validate financial records
  • Conduct security reviews

Customer funds shall remain the highest priority.

13. Major Service Outage

If a major outage occurs, Korven One may:

  • Activate incident management procedures
  • Prioritize critical services
  • Provide customer communications
  • Escalate operational response teams

14. Banking Partner Outage

If a banking partner experiences disruption, Korven One may:

  • Suspend affected settlement operations
  • Activate alternative banking procedures where available
  • Notify impacted users
  • Monitor treasury exposure

Treasury operations shall review liquidity impact.

15. Payment Network Failure

If a payment rail becomes unavailable, Korven One may:

  • Route transactions through available channels
  • Delay settlement activities
  • Restrict affected transaction types

Business continuity teams shall assess operational impact.

16. Natural Disaster Response

Examples:

  • Earthquakes
  • Hurricanes
  • Flooding
  • Severe Weather Events

Korven One may:

  • Activate remote operations
  • Prioritize employee safety
  • Protect customer data
  • Maintain essential services

17. Country-Level Disruption

Examples:

  • Internet Disruptions
  • Political Instability
  • Infrastructure Failures
  • Telecommunications Outages

Korven One may:

  • Activate contingency procedures
  • Increase operational monitoring
  • Protect treasury operations
  • Maintain communication channels

18. Data Backup Strategy

Korven One shall maintain:

  • Automated Backups
  • Encrypted Backups
  • Backup Verification Procedures
  • Periodic Restoration Testing

Backups shall be stored securely.

19. Recovery Testing

Korven One may periodically perform:

  • Backup Restoration Tests
  • Failover Testing
  • Incident Simulations
  • Tabletop Exercises
  • Treasury Recovery Exercises

Testing results may be documented and reviewed.

20. Communications Plan

Korven One may communicate with:

  • Customers
  • Merchants
  • Developers
  • Banking Partners
  • Service Providers
  • Regulatory Authorities

Communication procedures shall be coordinated and documented.

21. Employee Responsibilities

Employees involved in continuity planning must:

  • Follow response procedures
  • Participate in training
  • Report incidents promptly
  • Support recovery efforts

22. Third-Party Dependencies

Korven One may depend on:

  • Cloud Providers
  • Banking Partners
  • Identity Verification Providers
  • Payment Processors
  • Communication Providers

Business continuity planning shall consider third-party risks.

23. Governance

Korven One management shall oversee:

  • Business Continuity Planning
  • Disaster Recovery Planning
  • Recovery Testing
  • Risk Reviews
  • Incident Reviews

Periodic reviews shall be conducted.

24. Continuous Improvement

Following disruptions or testing activities, Korven One may:

  • Review lessons learned
  • Improve recovery procedures
  • Update controls
  • Enhance resilience

25. Policy Updates

This Plan may be updated periodically. Updates will be published through Korven One governance procedures.

26. Contact Information

Korven One Business Continuity Team

  • Email: bcdr@korvenone.com
  • Email: security@korvenone.com
  • Email: treasury@korvenone.com
  • Support: support@korvenone.com
  • Website: https://korvenone.com

27. Language

The official version of this Plan is the English version. Translations may be provided in:

  • Haitian Creole
  • French
  • Spanish

In case of conflict, the English version shall prevail.

Questions about this document?

Contact our team at legal@korvenone.com. For security matters, email security@korvenone.com.