The Resilience Operating System · 3-Layer Closed-Loop Architecture

Backup is not recovery.
Prove resilience
before the incident.

Récupérer works on top of what you already own: your AWS accounts, your snapshots, your AWS Backup. No agents, no rip-and-replace. It finds your true DR posture on day one, fixes the gaps in both resilience and wasted backup spend, and proves recovery with verified cleanroom drills before a real incident ever tests it.

DRPM Score: payments-core-prod Live
78/100
↑ +12 pts after Lazarus Mesh self-healing
Ransomware
76
Regional failure
94
Accidental deletion
82
Misconfiguration drift
68
Supply chain & IAM
88
Lazarus Mesh Status
Consensus ✓ verified
Air-Gap Vaults
LAG-01 ✓ enforced
Built for
/ / / /
Continuous validation
DORA (EU 2022/2554) NIST CSF 2.0 NIS2 Directive ISO 22301 / 27031 SOC 2 Type II PCI-DSS v4.0
The value loop

Find. Fix. Prove.

Récupérer turns the DR investments you already have into measurable, provable resilience, and pays for itself by reclaiming wasted protection spend along the way.

01 · Find

Know your true DR posture

Connect your AWS accounts read-only. Récupérer reconciles primary workloads with your existing AWS Backup and snapshot telemetry into one dependency graph, then scores real recoverability, surfacing gaps most teams never knew they had.

  • Agentless, multi-account, live. No rip-and-replace
  • DRPM score across ransomware, regional loss, deletion & drift
  • Maps the recovery blockers backups can't see: IAM, KMS, DNS, security groups
02 · Fix

Close resilience & cost gaps

Autonomous ResOps workflows remediate posture gaps and reclaim FinOps waste like orphaned recovery points, redundant snapshots, and over-provisioned retention, with human approval on anything that carries real blast radius.

  • Fixes DRPM gaps and FinOps waste in one loop
  • Blast-radius scoring & HITL gates on high-impact actions
  • Every change is scoped, least-privilege, and audit-logged
03 · Prove

Prove recovery, safely

Run real restores and cleanroom drills in isolated environments. Every restore captures a rollback point and passes a health check before it is trusted, so you can prove recovery without risking production.

  • Mandatory verification step on every restore and drill
  • Pre-restore rollback capture, so nothing runs without an undo
  • Isolated cleanroom drills; compliance evidence for DORA, NIST & SOC 2
Find Fix Prove continuously
Why Récupérer is Different

The Resilience Void.
Why Siloed Backup & Runbook Tools Leave You Exposed.

Traditional backup vendor products only see their own storage pools. Runbook automation tools execute blind scripts without state awareness. Récupérer is the closed-loop 3-layer system that unifies truth across primary and secondary sources.

Existing Backup Vendors

Blind to Primary Cloud State

Backup products (Veeam, Rubrik, AWS Backup) track snapshots in storage catalogs, but cannot see unmanaged primary workloads, missing IAM roles, KMS key accessibility, or whether security groups and Route 53 DNS records exist to boot the system.

✗ Incomplete estate visibility
Runbook Automation

Blind to Continuous Posture

Runbook engines (Rundeck, AWS SSM, Cutover) execute static shell scripts on demand. They lack live topological lineage, real-time RPO staleness calculations, blast-radius containment, and compliance evidence delivery.

✗ Passive, isolated execution
Récupérer Operating System

Closed-Loop Resilience Fabric

Unifies primary workloads with secondary protection telemetry into an interactive dependency graph. Validates customer DR intents (e.g. 4h RPO), streams audit evidence to Vanta, and proves recovery via sandboxed cleanroom drills.

✓ Proven recoverability in minutes
The platform

One platform.
Three operational pillars.

Recuperer operates continuously across your AWS estate: agentless, multi-account, and real-time. It maps deep topological lineage, continuously validates recovery capability against active threats, and executes autonomous remediation through multi-agent consensus.

01
Business system inventory & lineage Live
Business system Resources Accounts Coverage Drift
payments-core-prod 47 3 84% 6 changes
customer-portal 31 2 100% Clean
analytics-platform 89 4 71% 2 changes
auth-services 18 2 98% Clean
risk-engine 23 1 52% 11 changes
Layer 1 · Unified Asset & State Fabric

Primary Cloud Workloads & Secondary Telemetry Gelled

Recuperer maps every primary production resource across your AWS accounts, automatically reconciling dependencies between EC2, EBS, RDS, Aurora, DynamoDB, S3, KMS, and secondary protection pools. RPO staleness, retention expiry, and air-gapped vault locks are continuously tracked against live cloud state.

  • Agentless discovery bridging primary workloads and secondary tools
  • Multi-tier topological dependency lineage across accounts & regions
  • EC2 AMI protection inheritance & air-gap vault detection
  • Real-time state reconciliation preventing backup blind spots
02
DRPM Score: payments-core-prod 78 /100
Ransomware & cyber 3 open gaps · Air-Gap Vault LAG-01 active
76
Regional failure Cross-region replicated · 2 secondary regions
94
Misconfiguration drift 6 undocumented changes detected
68
Accidental deletion Versioning enabled · PITR active
82
Supply chain & IAM KMS key rotation & policy boundary verified
88
Mapped to DORA Art. 11/12 NIST CSF 2.0 NIS2 ISO 27031 2 gaps remaining

Layer 2 · Posture Assessment & Intent Engine

The DRPM Score is your continuous source of truth: real-time quantification of whether your workloads can survive ransomware, regional blackouts, KMS key deletion, and misconfiguration drift. Define custom resilience intents and controls, dynamically evaluate threat vectors against live telemetry, and deliver automated compliance evidence directly to platforms like Vanta, DORA, and NIST CSF.

  • Dynamic resilience intents & custom recovery controls
  • Continuous threat vector assessment with proactive mitigation strategies
  • Native delivery of real-time compliance posture to platforms like Vanta
  • Direct regulatory mapping (DORA Art. 11/12, NIST CSF 2.0, NIS2, ISO 27031)
03
Lazarus Mesh Remediation Workbench 7 open · 3 in progress · Est. +31 pts
Finding System Impact Action / Decision
Unencrypted Backup Vault Ransomware vector · KMS key policy missing
payments-prod +12 pts
Awaiting HITL Approval
Cross-Region Air-Gap Missing Regional failure · eu-west-1 secondary copy
analytics-platform +8 pts
Awaiting HITL Approval
DynamoDB PITR Disabled Human error · user-events table
payments-prod +5 pts
Lazarus Mesh Healed
EBS Snapshot Retention Mismatch Misconfiguration · 7d set, 30d required
risk-engine +6 pts
Lazarus Mesh Healed

Layer 3 · Resilience Operations (ResOps) & Cleanroom Drills

Moving beyond passive backup reporting and fragile manual runbooks, Recuperer's ResOps platform executes closed-loop mitigation workflows directly on primary data sources. Grounded in live topology and protected by deterministic 1–5 blast radius containment boundaries, it orchestrates automated ‘Proof of Life’ cleanroom recovery drills with complete human-in-the-loop (HITL) approval gates.

  • Closed-loop remediation executed directly on primary data sources
  • Deterministic 1–5 blast radius scoring to prevent cascading impact
  • Automated cleanroom recovery drills with ‘Proof of Life’ verification
  • Mandatory verification & pre-restore rollback capture on every restore
  • HITL approval gates, cryptographic audit trails & visual workflow studio
04
Protection spend & FinOps gaps Live
FinOps finding System Est. saving Action
Orphaned recovery points No live source resource · past retention need
analytics-platform $$$ Auto
Redundant snapshot copies Overlapping backup plans, same source
payments-core-prod $$ Auto
Over-provisioned retention Retention far exceeds the DR intent
customer-portal $$ Review

Realize value from what you already pay for

Resilience and cost are the same problem seen from two sides. Récupérer reads your existing protection spend against your actual recovery needs and reclaims the waste: orphaned recovery points, duplicate snapshots, and retention that outlives the DR intent, without ever weakening a posture that still matters.

  • Reclaim orphaned recovery points with no live source resource
  • Right-size retention to the DR intent, not a guess
  • Collapse redundant, overlapping backup plans
  • Every cost action is guarded by the DRPM score, so savings never lower resilience below intent
Autonomous Intelligence & MCP Interface

Lazarus Mesh.
Multi-agent consensus & natural-language DR intents.

Accessible via interactive chat, autonomous sentries, and Model Context Protocol (MCP) servers. Declare objectives in plain English: “Ensure 4-hour RPO across payment services”, and Lazarus continuously validates against live telemetry, evaluates blast radius containment, and executes closed-loop cleanroom remediation with human-in-the-loop safety.

Plan Synthesis

Topology-Grounded Synthesis

Remediation plans are formulated against live topological lineage, dependency ordering, and RPO/RTO SLAs, not generic playbooks. Every action is grounded in the actual state of your infrastructure at the moment of execution.

⚡ Topology-Grounded Synthesis
Blast Containment

Strict 1-5 Containment Scoring

Every proposed action is scored against a deterministic 1-5 blast radius scale before execution. Shared KMS keys, cross-account dependencies, and vault isolation boundaries are evaluated to prevent cascading impact.

🛡 Strict 1-5 Containment Scoring
Execution Governance

Policy-Gated Execution

Cryptographic policy invariants are enforced before any state change. High-blast or irreversible actions are held at a human-in-the-loop gate. Routine fixes execute autonomously with full audit attestation.

✍ Cryptographic Attestation
1 Drift Trigger
EventBridge / continuous scan
2 Topology Grounding
Postgres lineage & telemetry
3 Mesh Consensus
Orchestrator + 1-5 blast score
4 Gated Execution
Governor signed or HITL gate
5 Proof Verification
Live RPO & KMS verified
3-Layer Resilience Operating System

Every layer of resilience intelligence, unified.

A closed-loop 3-layer architecture: uniting primary workloads with secondary protection telemetry into continuous compliance signals, validated intents, and sandboxed cleanroom recovery.

Layer 3 · Resilience Operations (ResOps) Proof of Life Cleanroom Drills & HITL

ResOps Platform: Mitigation Workflows & Cleanroom Validation

Executes corrective mitigation runbooks and isolated sandboxed cleanroom DR validation drills directly against primary infrastructure. Restores snapshots in ephemeral quarantine VPCs, runs synthetic integrity checks, certifies exact RTO/RPO metrics, and tears down with zero idle spend. Restore-grade safety is enforced by design: every restore captures a rollback point first and must pass a verification step before it is trusted.

Layer 2 · Posture Assessment & Intent Engine Dynamic Intent Validation (4h RPO) · Automated Vanta & SOC 2 Feeds

Continuous Posture Scoring & DR Intent Validation

Continuously models threat vectors across ransomware, regional outages, unencrypted data, and IAM drift. Enables customers to dynamically enforce custom DR objectives (e.g. 4-hour RPO across payment databases), benchmark against DORA, NIST CSF 2.0, and NIS2, and stream live evidence to platforms like Vanta.

Layer 1 · Unified Asset & State Fabric Primary Workloads + Secondary Protection Gelled

Primary Cloud Assets & Secondary Augmentation Sync

Bridges the divide between primary production assets (RDS, EC2, DynamoDB, EKS, VPC, IAM, Route 53) and secondary protection telemetry (AWS Backup, Veeam, Datadog, CloudWatch). Reconstructs full-estate topological lineage and multi-tier dependencies into a single, continuous source of truth.

Why it matters

The cost of unproven DR, and the value of proving it.

Most organisations believe their DR posture is sound until an incident tests it. Récupérer turns that assumption into evidence, and the wasted spend into savings.

The risk today
Backup ≠
Recovery
A snapshot that exists is not a system that boots. IAM, KMS, DNS and dependencies decide whether you actually recover.
The risk today
Untested
Runbooks
Manual DR runbooks drift out of date between rare, high-stress tests, then fail when it counts most.
The value delivered
Proven
Recovery
Continuous DRPM scoring plus verified cleanroom drills turn "we think we can recover" into evidence you can show an auditor.
The value delivered
Reclaimed
Spend
Orphaned recovery points, duplicate snapshots and over-long retention become savings. Resilience that pays for itself.

Figures and named benchmarks are omitted until validated with production data. Récupérer reports your own numbers from your first scan: your DRPM score, your gaps closed, your spend reclaimed.

Platform Roadmap

AWS-native first. Every platform, next.

Recuperer is built deep into AWS before expanding anywhere else. Full-fidelity posture intelligence requires owning the primitives: backup APIs, IAM lineage, KMS key graphs, cross-account topology. We get that right on AWS first, then carry the same depth to Azure, GCP, and enterprise backup vendors.

Autonomous Resilience Operations

See your real DRPM score. On your own estate.

Connect read-only to the AWS accounts and backups you already have. In one scan, Récupérer shows your true DR posture, the gaps to fix, and the spend to reclaim, then proves recovery with verified drills. Deploy on AWS in under 30 minutes.